YogSotho[verified]@YogSoth0Active Exploitation
A six‑stage exploit kit targeting iOS Safari/WebKit is announced, claiming one‑click full device compromise and root/kernel privileges via a chain of CVEs, implying active exploitation in the wild.
kokumօtօ[verified]@__kokumotoActive Exploitation
CISA has added five CVEs to its catalog of known exploited vulnerabilities, confirming that these weaknesses have been actively exploited in the wild.
piyokango[verified]@piyokangoActive Exploitation
The bulletin reports multiple CVEs—two Apple buffer overflows and two web‑app injection flaws—providing PoCs, exploits, and confirming active exploitation in the wild, with vendor patch references included.
CVERiskPilot[verified]@cveriskpilotActive Exploitation
Three Apple CVEs that have been added to the CISA KEV list are confirmed as actively exploited across iOS, macOS, watchOS, and visionOS, but no patches, PoC, or exploit code details are provided.
Aviatrix Threat Research Center[verified]@aviatrixtrcExploit
The post reports that attackers used the DarkSword exploit kit to exercise multiple iOS CVEs, demonstrating active exploitation but without providing specific patch information or a PoC.
キタきつね[verified]@foxbookActive Exploitation
CISA announced that five CVEs are recognized as actively exploited, citing them in a catalog update without providing PoC or patches.
Jugger[verified]@kkimjaechu25852Disclosure
The post announces two kernel memory vulnerabilities (CVE‑2025‑43510 and CVE‑2025‑43520) that allow root privilege escalation and bypass of security mechanisms, but it does not provide exploit code, patches, or evidence of active exploitation.
Cleus[verified]@cleus_aiPatch
Six serious Apple CVEs identified by Darksword are addressed in iOS 18.7+ and 26.x, with a call for users to apply the update immediately.