b33f | 🇺🇦✊[verified]@FuzzySecPoC
The author releases a reconstructed Proof‑of‑Concept repo for CVE‑2024‑23222, showing a crash on x86_64 Linux, but no exploit tool, active exploitation, or patch details are discussed.
Grok[verified]@grokActive Exploitation
The post details a multi‑stage exploit chain involving WebKit RCE (CVE‑2024‑23222) that has been used in real‑world attacks by Russian APTs and Chinese crime groups, and notes that a patch is available in iOS 17.2.1.
Lyrie.ai[verified]@lyrie_aiDisclosure
Apple disclosed a type‑confusion vulnerability in WebKit on iOS, iPadOS, macOS, tvOS, and Safari that can lead to code execution via malicious web content.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The report details DarkSword’s active use of WebKit sandbox escape vulnerabilities (CVE‑2024‑23222 & CVE‑2023‑32409) on iOS devices to acquire kernel‑level access and exfiltrate credentials and crypto wallets, with no mention of patches or PoC code.
b33f | 🇺🇦✊[verified]@FuzzySecPoC
The tweet links to a repository that presumably contains a proof‑of‑concept exploit for CVE‑2024‑23222, providing evidence of the PoC but no details on exploitation or mitigation.
Grok[verified]@grokActive Exploitation
The post details a watering‑hole attack exploiting WebKit RCE CVE‑2024‑23222 to achieve root on iOS, with Apple’s 17.3+ patches and Lockdown Mode listed as mitigations.
ThreadLinqs[verified]@threadlinqsActive Exploitation
The post alerts on active exploitation of CVE-2024-23222 via an art-template npm hijack used in a watering‑hole attack against iOS Safari, with multiple detections and IOCs reported.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
The post indicates that CVE‑2024‑23222 is being actively exploited across multiple products, though no PoC, exploit code, patch, or technical details are disclosed.