ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Apple fixes exploited zero-day in all of its OSes (CVE-2023-38606)

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-38606CVE-2023-37450

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-37450
+1 in the same advisory: …38606
Arbitrary Code Execution in Apple WebKit (iOS, iPadOS, macOS, Safari, tvOS, watchOS)

CVE-2023-37450 is a high-severity (CVSS 8.8) arbitrary code execution vulnerability in Apple's WebKit browser engine, affecting iOS, iPadOS, Safari, macOS Ventura, tvOS, watchOS, and WebKitGTK. It is triggered when an affected device processes maliciously crafted web content — for example, when a user is lured into visiting an attacker-controlled webpage (user interaction is required, hence the UI:R CVSS vector). Successful exploitation grants the attacker arbitrary code execution within the web-content/browser context, the typical entry point for full iPhone, iPad, or Mac compromise chains. Anyone running iPhone OS/iPadOS earlier than 16.6, Safari earlier than 16.5.2, macOS Ventura earlier than 13.5, tvOS earlier than 16.6, watchOS earlier than 9.6, or unpatched WebKitGTK builds is affected. Apple reports the issue may have been actively exploited before it was patched, CISA added it to the KEV catalog on 2023-07-13, and EPSS assigns an 18.9% probability (97th percentile) of exploitation over the next 30 days.

Do: Upgrade immediately to iOS 16.6 / iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6, and watchOS 9.6, or apply the latest available patch for older OS branches on devices that cannot take the 16.x/Ventura updates; this is a CISA KEV entry with a federal remediation requirement. Because exploitation occurs through normal web browsing, patching is the only reliable mitigation — avoid untrusted websites as an interim measure. WebKitGTK users should update to the latest patched WebKitGTK release and verify that dependent applications have been rebuilt against the fixed library.

8.8
group max
19% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 16.6
  • Apple iPadOS All versions prior to iPadOS 16.6
  • Apple Safari All versions prior to Safari 16.5.2
  • +4 more
mass≈2 billion active Apple devices (WebKit is the web engine for iOS/iPadOS, Safari, tvOS and watchOS); no public counts of exploited devices are known
Full article314 words · extracted from helpnetsecurity.com · click to collapse

Apple has patched an exploited zero-day kernel vulnerability (CVE-2023-38606) in iOS, iPadOS, macOS, watchOS and tvOS.

CVE-2023-38606

CVE-2023-38606 fix has been backported

In early July, Apple fixed an actively exploited zero-day vulnerability (CVE-2023-37450) in WebKit.

The vulnerability has been patched via a Rapid Security Response update in iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1, and in Safari (16.5.2) via a regular update, thus also delivering the fix to users of older macOS versions (macOS Big Sur and macOS Monterey).

Those patches have now been backported and included in:

The fix was not included in Safari 16.6 (since it was covered by the previous Safari 16.5.2 update), nor in macOS Monterey 12.6.8 and macOS Big Sur 11.7.9 (for the same reason).

About CVE-2023-38606

The July 24 security updates have fixed a variety of vulnerabilities affecting the various OS releases, including another zero-day vulnerability exploited by attackers (CVE-2023-38606).

CVE-2023-38606 is a kernel vulnerability that may allow a malicious app to modify sensitive kernel state. “Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1,” Apple commented.

The vulnerability was reported by Kaspersky researchers Valentin Pashkov, Mikhail Vinogradov, Georgy Kucherin, Leonid Bezvershenko, and Boris Larin, and forms a part of the exploit chain used by iOS spyware the researchers dubbed TriangleDB. (Two vulnerabilities used in the same chain have been fixed by Apple in late June.)

Attacks leveraging the TriangleDB spyware seem to have been very targeted; Kaspersky has provided a tool users can use to check whether they are among the victims.

Users of Apple devices are advised to implement the latest updates as soon as possible.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/07/25/cve-2023-38606/