Apple, Microsoft, and Qualcomm Just Issued Emergency Patches for Zero-Days Exploited in Wild Attacks

Post date: February 12, 2026 · Discovered: April 23, 2026 · 6 posts, 0 comments

Major tech giants—Apple, Microsoft, and Qualcomm—are scrambling to deploy emergency security updates. These patches address multiple zero-day vulnerabilities across core platforms, including iOS, WebKit, Windows MSHTML, and DSP services.

The narrative centers on documented, active exploitation. Specific reports detail Apple fixing multiple zero-day flaws in WebKit and iOS, while Microsoft closed an MSHTML vulnerability that was exploited for a documented eighteen months. Qualcomm also patched a critical DSP zero-day across its chipsets.

The overwhelming weight of evidence points to constant, severe threat activity. The community views these disclosures not as routine maintenance, but as evidence of advanced, persistent, and widespread exploitation attempts across the entire mobile and desktop ecosystem.

Key Points

#1Microsoft patched an MSHTML zero-day exploited for an extended period.

The specific vulnerability allowed malicious scripts to run for eighteen months, as noted in the thread (lemmydev2).

#2Apple confirmed patching multiple zero-day flaws in iOS and WebKit.

Updates were pushed to address vulnerabilities actively exploited against iPhones.

#3Qualcomm addressed a flaw in its DSP services.

The company issued a patch for a zero-day vulnerability impacting multiple chipsets.

#4The threat level is characterized by active, widespread exploitation.

Multiple vendors are responding to vulnerabilities confirmed to be used in live attacks, indicating sophisticated threat actors.

Source Discussions (6)

This report was synthesized from the following Lemmy discussions, ranked by community score.

25
points
Windows MSHTML zero-day used in malware attacks for over a year
[email protected]·1 comments·7/10/2024·by lemmydev2·bleepingcomputer.com
11
points
Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
[email protected]·0 comments·2/12/2026·by lemmydev2·bleepingcomputer.com
6
points
Apple fixes two new iOS zero-days exploited in attacks on iPhones
[email protected]·0 comments·3/5/2024·by lemmydev2·bleepingcomputer.com
5
points
Qualcomm patches high-severity zero-day exploited in attacks
[email protected]·0 comments·10/7/2024·by lemmydev2·bleepingcomputer.com
4
points
Apple fixes two zero-days exploited in targeted iPhone attacks
[email protected]·0 comments·4/16/2025·by lemmydev2·bleepingcomputer.com
4
points
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
[email protected]·0 comments·3/11/2025·by lemmydev2·bleepingcomputer.com