ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple Issues Patch for Remote Hacking Bug Affecting Billions of its Devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1782
Race Condition Privilege Escalation in Apple iOS, macOS, watchOS, and tvOS

A race condition caused by improper locking (CWE-667) in Apple's operating systems could allow local privilege escalation. The flaw is triggered by a malicious application already running on the device that exploits a timing race; exploitation requires only low local privileges and no user interaction, though the attack complexity is rated high. A successful attacker gains elevated privileges with high impact to the confidentiality, integrity, and availability of the device. Users of iPhone, iPad, Mac, Apple Watch, and Apple TV running versions earlier than iOS/iPadOS 14.4, macOS Big Sur 11.2 (or the 2021-001 security updates for Catalina and Mojave), watchOS 7.3, and tvOS 14.4 are affected. Apple reported the issue as actively exploited in the wild, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and no public proof-of-concept is known.

Do: Upgrade to iOS/iPadOS 14.4, watchOS 7.3, and tvOS 14.4; on Macs, upgrade to macOS Big Sur 11.2 or apply Security Update 2021-001 for Catalina and Mojave. As an interim mitigation, avoid installing untrusted applications, since exploitation requires a malicious local app. This vulnerability is in the CISA KEV catalog, so organizations subject to the required action should verify that all managed Apple devices are running the patched versions.

7.02% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 14.4
  • Apple iPadOS versions prior to iPadOS 14.4
  • Apple macOS Big Sur versions prior to macOS Big Sur 11.2
  • +4 more
masshundreds of millions of Apple devices (estimate based on Apple's active installed base exceeding 1 billion devices)
CVE-2021-1844
A memory corruption issue was addressed with improved validation.

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, Safari 14.0.3 (v. 14610.4.3.1.7 and 15610.4.3.1.7), watchOS 7.3.2, macOS Big Sur 11.2.3. Processing maliciously crafted web content may lead to arbitrary code execution.

NVD description · AI analysis pending
8.82%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2021-1870
+1 in the same advisory: …1871
WebKit Logic Flaw Enables Remote Code Execution on iOS, iPadOS, and macOS

CVE-2021-1870 is a logic flaw in Apple's WebKit browser engine, addressed in iOS 14.4, iPadOS 14.4, macOS Big Sur 11.2, and Security Update 2021-001 for Catalina and Mojave via improved restrictions. A remote attacker can trigger the flaw through hostile web content processed by WebKit on a vulnerable device, with no authentication or privileges required per the CVSS 3.1 network-vector scoring. Successful exploitation allows arbitrary code execution on the affected device. All users of iPhone OS/iPadOS prior to 14.4 and macOS prior to the listed fixes are affected, as WebKit ships with every Apple device, and WebKitGTK/Fedora users of the same engine are also potentially impacted. Apple reported the issue may have been actively exploited in the wild as a zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03.

Do: Upgrade iPhones/iPads to iOS/iPadOS 14.4, Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave. Fedora/WebKitGTK users should install the distribution's updated WebKitGTK packages. The issue is on the CISA KEV list with a required action of applying vendor updates; no public PoC or specific mitigation is known, so patching is the primary remediation.

9.88% KEV
  • apple iphone os (iOS) versions prior to iOS 14.4
  • apple ipados versions prior to iPadOS 14.4
  • apple macos (Big Sur) versions prior to macOS Big Sur 11.2
  • +4 more
masson the order of 1+ billion Apple devices (WebKit ships in every iPhone, iPad, and Mac)
Full article300 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 09, 2021

Apple has released out-of-band patches for iOS, macOS, watchOS, and Safari web browser to address a security flaw that could allow attackers to run arbitrary code on devices via malicious web content.

Tracked as CVE-2021-1844, the vulnerability was discovered and reported to the company by Clément Lecigne of Google's Threat Analysis Group and Alison Huffman of Microsoft Browser Vulnerability Research.

According to the update notes posted by Apple, the flaw stems from a memory corruption issue that could lead to arbitrary code execution when processing specially crafted web content. The company said the problem was addressed with "improved validation."

The update is available for devices running iOS 14.4, iPadOS 14.4, macOS Big Sur, and watchOS 7.3.1 (Apple Watch Series 3 and later), and as an update to Safari for MacBooks running macOS Catalina and macOS Mojave.

The latest development comes on the heels of a patch for three zero-day vulnerabilities (CVE-2021-1782, CVE-2021-1870, and CVE-2021-1871) that was released in January. The weaknesses, which allow an attacker to elevate privileges and achieve remote code execution, were later exploited by the team behind the "unc0ver" jailbreak tool to unlock almost every single iPhone model running 14.3.

It's worth noting that Huffman was also behind the discovery of an actively exploited zero-day bug in the Chrome browser that was addressed by Google last week. But unlike the Chrome security flaw, there is no evidence that CVE-2021-1844 is being exploited by malicious hackers.

Users of Apple devices or those running a vulnerable version of Chrome are advised to install the updates as soon as possible to mitigate the risk associated with the flaws.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/03/apple-issues-patch-for-remote-hacking.html