Apple issues patch for desktop Safari browser and OS X to fix zero-day vulnerabilities, which are similar to those used in NSO's iOS attack discovered last week
Lorenzo Franceschi-Bicchierai / Motherboard :
Context & Ripple Effects
This 2016 patch is the opening data point in a pattern the later coverage makes explicit: Apple fixing zero-days that trace back to NSO Group's spyware tooling. The desktop Safari/OS X fixes matter because they show the same exploit chain NSO used on iOS was live on Macs too — the threat was never mobile-only.
Seven years on, the pattern is unchanged in kind if larger in scale: Citizen Lab-attributed Pegasus delivery via two zero-days forced updates across macOS, iOS, iPadOS, and watchOS in September 2023, and by December Apple had logged twenty zero-day fixes for the year in emergency releases. The 2016 desktop patch is where that cadence started.
First-order effects
- Mac users running Safari get immediate protection against the same class of exploit NSO deployed against iOS, closing a desktop attack surface that had been exposed alongside last week's mobile discovery.
Second-order effects
- NSO and its government customers lose a working exploit chain and must source or develop replacements, raising the per-target cost of commercial spyware operations — while researchers like Citizen Lab gain a documented template for tracing future attacks back to vendor tooling.
Third-order effects
- Commercial spyware becomes a structural driver of platform vendors' security cadence: what began as a single desktop-and-mobile patch in 2016 hardens into the recurring cross-platform emergency-update cycle visible throughout Apple's 2021–2023 record, with attribution firms acting as de facto quality assurance on surveillance vendors' inventory.
The trend: Commercial spyware vendors' zero-day purchases are turning platform security from scheduled maintenance into a continuous, attribution-driven arms race between Apple and the surveillance industry.