The discoveries were made by security researchers Georgy Kucherin, Leonid Bezvershenko, and Boris Larin at Kaspersky.
They explain in a blog post how the implant known as TriangleDB is deployed on an iOS device after attackers exploited a kernel vulnerability to gain root privileges.
A zero-day vulnerability refers to a security flaw in a software that is unknown to the software developer – meaning developers have “zero-days” to fix it before it is exploited by attackers.
The two found by Kaspersky researchers are identified as CVE-2023-32434 and CVE-2023-32435. The former involves a kernel bug that could lead to unauthorised access, while the latter is a WebKit bug which enables remote code execution (RCE) when processing web content.
An anonymous researcher identified the third vulnerability known as CVE-2023-32439 which, like CVE-2023-32435, is an RCE that can be triggered by crafted web content and may have been exploited.
The TriangleDB implant which is deployed through the kernel vulnerability is deployed in memory. This means that all traces of the implant are lost when the device is rebooted. Attackers have to reinfect the device from the start by sending an iMessage, which may not even need user interaction to work.
The implant’s capabilities include interacting with the filesystem by creating, modifying, exfiltrating and removing files, as well as listening and terminating processes, accessing the keychain (passwords), and monitoring user location.
According to Apple, the kernel affected watchOS 8.8.1 and 9.5.2, macOS Big Sur 11.7.8, macOS Monterey 12.6.7, iOS 16.5.1, and iPadOS 16.5.1. The WebKit bug and the kernel bug both impact macOS Ventura 13.4.1, iOS 15.7.7, and iPadOS 15.7.7.
Device-wise, the kernel and WebKit could be found in all iPhone 6s models, all iPhone 7 models, iPhone SE 1st generation, iPad Air 2, iPad mini 4th generation, and iPod touch 7th generation.
Recommended
- Cloud First ‘23 | The Whats, Whys, and Hows of Cloud Centres of Excellence
- NCSC Removes Thousands of Email Scams With Reporting Service
- Cabinet Office Engages AND Digital to Enhance its Find a Grant Service
Ray Kelly, fellow at the Synopsys Software Integrity Group said: “Security-focused updates like this really stress the importance of enabling automatic iOS updates to ensure you have the latest software that keeps your device safe. However, since some users choose to disable these automatic updates, malicious actors will always have a vast amount of vulnerable targets.”
Apple responded to these zero-day vulnerabilities yesterday in its newest iOS update, and urged all affected users to update their devices to the latest software versions to mitigate the risks associated with these exploits.
“Apple has a great track record when it comes to addressing critical vulnerabilities in its software quickly to help its users stay protected. This is critically important since Apple users do not have a way to protect themselves from malicious websites that may be actively exploiting in the wild, like this specific WebKit vulnerability,” said Kelly.





