When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.

), and exfiltrating web app data (web app history and similar).

Furthermore, the targets are only macOS 10.13.3 users, so those with macOS 14 should be safe.

Illustration of a laptop with a magnifying glass exposing a beetle on-screen

To compromise the endpoints, the attackers are leveraging two known WebKit flaws, tracked as CVE-2018-4233 and CVE-2018-4404.

A surveillance framework differs somewhat from your average malware, by using different plugins.

For the Android version, LightSpy used 13 plugins, while for iOS - 16.

ViaBleepingComputer

More from TechRadar Pro