Apple releases emergency security updates for iOS, iPadOS, macOS, and watchOS to patch three zero-day vulnerabilities, for a total of 16 zero-days fixed in 2023
Attacks Underway Lance Whitney / ZDNet : Apple issues emergency security updates for iPhone, iPad, and Apple Watch Kevin Poireault / Infosecurity : mWISE: Why Zero Days Are Set for Highest Year on Record Apple Support : About the security content of iOS 17.0.1 and iPadOS 17.0.1 Pierluigi Paganini / Security Affairs : Recently patched Apple and Chrome zero-days exploited to infect devices in Egypt with Predator spyware Mihir Bagwe / DataBreachToday.com : Apple Fixes Bugs That Infected Egyptian Politician's iPhone Chris Williams / The Register : Apple squashes security bugs after iPhone flaws exploited by Predator spyware Steve Zurier / SC Media : Apple issues emergency patches on three new exploited zero-days National Vulnerability Database : CVE-2023-41992 Detail — UNDERGOING ANALYSIS — This vulnerability is currently undergoing analysis … Kevin Raposo / KnowTechie : Urgent! iOS 17 threat uncovered - update your Apple devices now Johannes Ullrich / SANS Internet Storm Center, InfoCON : Infocon: green — This update patches three already exploited vulnerabilities: Dark Reading : Apple Fixes 3 More Zero-Day Vulnerabilities Michael Simon / Macworld : If you're waiting to upgrade to iOS 17, go get iOS 16.7 right now Cynthia Brumfield / Metacurity : Apple Issues Emergency Patches to Fix Three New Zero-Day Flaws TechRadar : Apple releases emergency fix for three serious iOS and macOS bugs — update your Mac and iPhone now Alex Blake / Digital Trends : Update your Apple devices now to fix these dangerous exploits Zeljka Zorz / Help Net Security : Apple fixes 3 zero-day vulnerabilities exploited to compromise iPhones Eduard Kovacs / SecurityWeek : Apple Patches 3 Zero-Days Likely Exploited by Spyware Vendor to Hack iPhones Leigh Mc Gowran / Silicon Republic : Apple releases iOS 17 patch to fix potentially exploited flaws Juli Clover / MacRumors : Apple Releases iOS 17.0.1 and iPadOS 17.0.1 With Bug Fixes, Plus iOS 17.0.2 for iPhone 15 Models Mike Wuerthele / AppleInsider : Apple rolls out iOS 17.0.1, iPadOS 17.0.1, watchOS 10.0.1 updates Ashwin / Ghacks : Apple patches 3 actively exploited security issues in iOS 17, iPadOS 17 and macOS 13 David Balaban / MacSecurity.net : Apple patches an actively exploited UXSS bug in iOS, iPadOS, and watchOS The Hacker News : Apple Rushes to Patch 3 New Zero-Day Flaws: iOS, macOS, Safari, and More Vulnerable Pierluigi Paganini / Security Affairs : Apple rolled out emergency updates to address 3 new actively exploited zero-day flaws Lindsey O'Donnell-Welch / Decipher : Apple Fixes Trio of Actively Exploited Bugs Alan Friedman / PhoneArena : Apple suggests you install ASAP iOS, iPadOS 17.0.1 and watchOS 10.0.1 for security reasons Michael Kan / PCMag : Yikes: Apple Patches 3 New Zero-Day Exploits for iOS, MacOS Anthony Spadafora / Tom's Guide : Apple fixes three serious bugs in iOS and macOS — update your iPhone and Mac right now Imran Hussain / iThinkDifferent : Apple releases iOS 17.0.1 and iPadOS 17.0.1 with critical security fixes Jake Peterson / Lifehacker : iOS 17 Has Security Risks Already Davey Winder / Forbes : iOS 17.0.1: Critical Security Update Warning For All iPhone Users Adam Engst / TidBITS : OS Security Updates Address Three More Exploited Vulnerabilities Paul Horowitz / OS X Daily : iOS 16.7 & iPadOS 16.7 Updates Released with Security Fixes Mastodon: @YourAnonNews@nerdculture.de : It doesn't matter what operating system you use, update your browsers, email client, discord app, twitch app, password manager...just update everything! — Incomplete disclosures by Apple and Google create “huge blindspot” for 0-day hunters — https://arstechnica.com/... Seth Michael Larson / @sethmlarson@fosstodon.org : 🚨 Please update your phones to iOS 16.7, these vulns are being exploited in the wild via webpages. — https://www.bleepingcomputer.com/ ... X: John Scott-Railton / @jsrailton : 🚨UPDATE your @Apple products now! We @citizenlab w/TAG's @maddiestone caught #predator spyware attacks against a prominent pro-democracy Egyptian politician after he announced presidential ambitions. Apple rushed a patch. It gets crazier 1/ https://citizenlab.ca/... [image] Aaron Zollo / @zollotech : When Apple releases an update and says there are Bug Fixes it would be extremely helpful if they told us what those are. Not sure why they don't really do that anymore very much. It would be a better experience if we knew though. Max Weinbach / @maxwinebach : I wouldn't update your iPhone to this if you are getting a 15 tomorrow, update after you setup your iPhone 15 Otherwise, it'll need to update the iPhone 15 before transferring data. @theapplehub : Apple has released iOS 17.0.1 which includes bug fixes and important security updates for the iPhone 15 models Have you updated to iOS 17 yet? [image] Forums: Hacker News : 0-days exploited by commercial surveillance vendor in Egypt r/technews : Incomplete disclosures by Apple and Google create “huge blindspot” for 0-day hunters. r/cybersecurity : Apple emergency updates fix 3 new zero-days exploited in attacks r/technology : Incomplete disclosures by Apple and Google create “huge blindspot” for 0-day hunters | No one mentioned that libwebp, a library found in millions of apps, was a 0-day origin. r/InfoSecNews : Apple emergency updates fix 3 new zero-days exploited in attacks r/jailbreak : Apple emergency updates fix 3 new zero-days exploited in attacks
Context & Ripple Effects
Apple’s emergency release follows a recurring cross-platform patch pattern: a WebKit zero-day fix earlier in 2023 and prior updates for actively exploited flaws across Apple operating systems. The reported total of 16 fixes in 2023 makes this more than an isolated maintenance release.
The immediate reports also connect the vulnerabilities to Predator spyware targeting an Egyptian politician’s iPhone, echoing the earlier use of multiple iPhone zero-days against an activist and underscoring why rapid patch availability matters for high-risk users.
First-order effects
- iPhone, iPad, Mac, and Apple Watch users receive patches for three actively relevant zero-days; unpatched devices remain exposed until the updates are installed.
- Apple must sustain emergency release and support operations across four operating systems, while the disclosed fixes reduce the usable life of the affected exploit chains.
Second-order effects
- Organizations managing Apple fleets face renewed pressure to shorten update deployment cycles, particularly for users likely to be targeted by spyware.
- Spyware operators relying on the patched vulnerabilities must replace or rework access methods, raising the operational cost of campaigns tied to those flaws.
Third-order effects
- If repeated emergency patches continue, endpoint security will increasingly depend on the speed of vendor remediation and customer deployment rather than platform hardening alone.
- The apparent use of zero-days in targeted surveillance reinforces scrutiny of commercial spyware supply chains and the protections available to politically exposed users.
The trend: This is one data point in the continuing contest between rapidly patched consumer-device ecosystems and targeted spyware operations that depend on scarce zero-day access.