ZeroHour
The Recordpublished ()ingested

Mozilla, CISA urge users to patch Firefox security flaw

criticalVulnerability exploited in the wildimportance 60CVE-2023-4863CVE-2023-41064

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41064
ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution

CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs.

Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices.

7.845% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion)
CVE-2023-4863
Out-of-Bounds Write in Google Chromium WebP Image Codec Actively Exploited

CVE-2023-4863 is a heap-based buffer overflow (CWE-787) in the WebP image codec used by Google Chromium, allowing a remote attacker to write outside the intended bounds of allocated memory. It is triggered when a user visits a crafted HTML page containing malicious WebP image data, so no authentication or special privileges are required, only that the victim loads attacker-controlled content in an affected application. Successful exploitation gives the attacker an out-of-bounds memory write in the affected process, which can lead to application crashes or memory corruption with the potential for code execution. Exposure is unusually broad because, per the advisory, the flaw can affect any application that uses the WebP codec, meaning the browsing public and any software bundling WebP decoding are plausibly in scope. The flaw was added to the CISA KEV catalog on 2023-09-13, indicating confirmed exploitation in the wild; EPSS assigns it a 100% probability of exploitation within 30 days, ransomware use is unknown, and no public proof-of-concept is known.

Do: Update Google Chrome and all other Chromium-based browsers to the latest stable release containing the WebP fix (the patched Chrome 116.0.5845.187 shipped in September 2023), and update or rebuild any other software that bundles the WebP/libwebp codec (fixed in libwebp 1.3.2). Until patching is complete, treat untrusted web content as the attack vector and, per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of affected software if mitigations are unavailable. Verify remediation by checking installed browser and application versions against the vendor advisories.

8.8100% KEV PoC ×4
  • Google Chromium WebP
mass~3+ billion users (Chromium-based browsers account for roughly two-thirds of global browser usage)
Full article418 words · extracted from therecord.media · click to collapse

Mozilla released an advisory this week warning users of a vulnerability affecting its popular web browser and email client.

Exploitation of the bug would allow a hacker to take control of an affected system, officials at the Cybersecurity and Infrastructure Security Agency (CISA) said in their own notice.

Tagged as CVE-2023-4863, the vulnerability was discovered by Apple Security Engineering and Architecture (SEAR) and the Citizen Lab at The University of Toronto, according to Mozilla.

Mozilla rated the vulnerability critical and said it is aware of it being exploited in other products in the wild. The company addressed the issue in patches to its Firefox, Firefox ESR and Thunderbird products.

The issue pertains to the WebP code library, which is used by multiple browsers and image editors.

Google – which released a patch addressing the bug for its Chrome browser – said it is also aware that an exploit for CVE-2023-4863 exists in the wild. Microsoft published its own advisory about it, noting that it affects the Microsoft Edge browser.

Little information was provided about how it is being exploited, but CISA added the bug to its known exploited vulnerabilities list on Wednesday, giving federal civilian agencies until October 4 to patch it.

Menlo Security co-founder Poornima DeBolle said the issue affects all of the major browsers and is an example of why vulnerabilities affecting browsers can often be a “whack-a-mole game for security teams.”

“Browsers are distributed and used all over organizations, making them a challenge to patch. A single vulnerability in an open source package is putting everyone at risk. Attackers know this and are finding more creative ways to exploit this weak link,” DeBolle said.

Several experts said the fact that the vulnerability was discovered by Citizen Lab indicated that it may be tied to two zero-click exploits disclosed last week known as “BlastPass.”

One bug, tracked as CVE-2023-41064, allowed devices — including some iPhones, iPads, Macs, and Apple Watches — to become vulnerable to attack when processing “a maliciously crafted image,” Apple said. It affects the Image I/O framework, specifically.

Citizen Lab did not respond to requests for comment about whether CVE-2023-4863 was tied to the BlastPass findings.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/mozilla-cisa-urge-users-to-patch-firefox-vulnerability