All CosmicBytez Labs articles tagged #Apple, across news, security advisories, how-to guides, and projects.
Apple warned iPhone users in 110 countries of mercenary spyware attacks. Enable Lockdown Mode and update iOS immediately if you receive an alert.
This week's security roundup: Apple caps bug bounty submissions as AI-generated reports surge, NC ports hit by cyberattack, hedge funds targeted by vishing, and a QuickFox VPN supply chain attack.
A critical authentication bypass vulnerability in the WooCommerce - Social Login WordPress plugin allows unauthenticated attackers to log in as any registered user by exploiting a missing JWT signature verification in the Apple login handler.
Three plaintiffs have filed suit against Apple in California federal court after a fraudulent Sparrow Wallet impersonator on the App Store harvested their Bitcoin seed phrases, draining approximately $1.835 million. The lawsuit alleges Apple had prior knowledge of the fake and failed to act.
A critical memory corruption vulnerability in macOS allows a malicious application to corrupt memory of a system process. Apple patched the flaw in macOS Sonoma 14.8.8 and macOS Tahoe 26.6 with a CVSS score of 9.8.
A critical use-after-free vulnerability affects iOS, iPadOS, macOS, tvOS, and watchOS. A malicious app can trigger unexpected system termination. Apple patched the flaw across all platforms in the July 2026 security release wave.
A critical race condition in macOS enables a remote attacker to cause unexpected system termination or corrupt kernel memory. Apple patched the flaw in macOS Sequoia 15.7.8, Sonoma 14.8.8, and Tahoe 26.6 in July 2026.
Jamf Threat Labs has discovered PamStealer, a sophisticated two-stage macOS infostealer that impersonates the Maccy clipboard manager, delivers a...
This week's security roundup covers AI compute theft, a newly discovered Apple Mail vulnerability, the emerging BlueHammer ransomware group, and 14...
Qihoo 360 unveils Tulongfeng — a Chinese rival to Anthropic's Mythos AI vulnerability finder; the World Leaks ransomware group dumps 630 GB from Tata...
World Leaks — the rebranded extortion wing of the defunct Hunters International ransomware group — has leaked Apple manufacturing data stolen from Tata...
The Usbliter8 exploit targets a hardware-level flaw in Apple A12 and A13 SecureROM boot chains that cannot be patched via software updates, leaving...
This week's security roundup covers Apple's patch for a Beats headphones eavesdropping vulnerability, the DOT closing its investigation into Delta's...
Security researchers at Paradigm Shift have published a working exploit called usbliter8 that achieves arbitrary code execution inside the SecureROM of...
Apple has open-sourced its implementations of two NIST-standardized quantum-secure algorithms — ML-KEM and ML-DSA — including formal verification tooling that.
Apple has revealed it blocked more than $11 billion in fraudulent App Store transactions over the past six years, including $2.2 billion in 2025 alone,...
Apple's annual transparency report reveals the company blocked over 2 million App Store submissions, 1.1 billion accounts, and $2.2 billion in potentially...
A CVSS 7.5 denial-of-service vulnerability in Apple iOS and iPadOS allows a remote attacker to exhaust device resources and crash the operating system...
Threat actors are exploiting Apple's legitimate account change notification system to embed fake iPhone purchase scams inside genuine Apple emails,...
A crafted short X-Wing HPKE encapsulated key can trigger an out-of-bounds read in the C decapsulation path of Apple's swift-crypto library, potentially...
Apple has extended security update eligibility to additional iPhone models still running iOS 18, enabling more devices to receive protections against the...
This week's cybersecurity roundup covers long-running telecom espionage operations reaching courtrooms, resurging LLM jailbreak techniques, Apple's UK age...
CISA orders federal agencies to patch five actively exploited vulnerabilities by April 3, including three Apple flaws linked to the DarkSword iOS exploit...
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locking vulnerability allowing a malicious app to cause unexpected changes in...
Apple has patched CVE-2026-20700, a memory corruption vulnerability in dyld used in 'extremely sophisticated' targeted attacks. Discovered by Google TAG,...
Apple releases emergency patches across all platforms for a memory corruption vulnerability in the Dynamic Link Editor (dyld) that was exploited in...
Apple has released security updates for iOS, macOS, watchOS, and tvOS addressing multiple actively exploited vulnerabilities. Users urged to update immediately.