CVE-2023-37450
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: Feb. 18, 2026
18 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.07%
probability
This CVE has a 0.07% probability
of being exploited in the next 30 days.
0%
Top 22.1th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroUnspecified memory corruption
Google Project Zero
Patched
July 10, 2023
Reported by
???
Root Cause Analysis
???
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
BleepingComputer
Feb 10, 2025
Apple fixes this year’s first actively exploited zero-day bug
BleepingComputer
Jan 27, 2025
Apple fixes iOS Kernel zero-day vulnerability on older iPhones
BleepingComputer
Oct 12, 2023
Apple emergency update fixes new zero-day used to hack iPhones
BleepingComputer
Oct 04, 2023
Apple fixes new zero-day used in attacks against iPhones, Macs
BleepingComputer
Jul 24, 2023
Apple releases emergency update to fix zero-day exploited in attacks
BleepingComputer
Jul 10, 2023
Apple fixes two zero-days used in attacks on Intel-based Macs
BleepingComputer
Nov 19, 2024
Apple re-releases zero-day patch after fixing browsing issue
BleepingComputer
Jul 12, 2023
Apple emergency updates fix 3 new zero-days exploited in attacks
BleepingComputer
Sep 21, 2023
Apple discloses 2 new zero-days exploited to attack iPhones, Macs
BleepingComputer
Sep 07, 2023
Apple fixes two new iOS zero-days exploited in attacks on iPhones
BleepingComputer
Mar 05, 2024
Apple fixes first zero-day bug exploited in attacks this year
BleepingComputer
Jan 22, 2024
Apple emergency updates fix recent zero-days on older iPhones
BleepingComputer
Dec 11, 2023
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
BleepingComputer
Mar 11, 2025
Apple fixes two new iOS zero-days in emergency updates
BleepingComputer
Nov 30, 2023
Apple backports BLASTPASS zero-day fix to older iPhones
BleepingComputer
Sep 12, 2023
Recently patched Apple, Chrome zero-days exploited in spyware attacks
BleepingComputer
Sep 22, 2023
Signal Intelligence
Confidence
92%
EPSS
0.07%
Mentions
18
Last Seen
Mar 11, 2025
CNA Information
Analyst Note
CVE-2023-37450 demonstrates clear indicators of active exploitation with confirmed zero-day status from Google Project Zero, high CVSS score (8.8), and multiple credible reports describing sophisticated attacks. Apple's official statement acknowledging active exploitation and issuing patches across multiple platforms further corroborates the confirmed classification.
Triage Info
Decided atFeb 18, 2026