securityonline.info 24 Sept 2026, 06:24 UTC

Fake SEND Notices Exploit iPhones Through Safari Zero Click Attack

Fake SEND Notices Exploit iPhones Through Safari Zero Click Attack
CyberSIXT Evidence Panel Source marked as original reporting

D 3Lab has reported an Italian phishing campaign that disguises malicious links as notifications from SEND, the country’s digital public-notice service. Messages claim that recipients have an outstanding legal or administrative document and direct them to a convincing copy of the pagoPA SEND portal. The fraudulent site presents a fake anti-bot check and uses Socket.IO to communicate with operators, who can change requests for payment-card details or verification codes based on victims’ replies.

The page also contains a hidden iframe connecting to an exploitation server. According to D3Lab, the browser itself is the entry point: no application installation or attachment opening is required. The server fingerprints the device and delivers a three-stage exploit chain against Safari’s WebKit engine, targeting iOS 13 through iOS 17.2.1. The stages attempt to obtain memory read/write access, bypass Pointer Authentication Code protections and escape the Safari sandbox.

If successful, a modified Coruna Pro V2 toolkit can collect SMS messages, call history, contacts, Safari bookmarks, location history and iOS Keychain data, then send it to command-and-control infrastructure.

The operators’ console, titled “Lü Technology Console API”, is written in Chinese and includes the Telegram handle “@ojishu”, but researchers could not attribute the campaign to a particular country or group. The reported response is to update iPhones beyond iOS 17.2.1, use the official portal at cittadini.notifichedigitali.it and consider Lockdown Mode for higher-risk users.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline