Apple addresses three zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-30665 +1 in the same advisory: …30663 | Memory Corruption in Apple WebKit Enables RCE on iOS, macOS, tvOS, watchOS CVE-2021-30665 is a memory corruption flaw (CWE-787, out-of-bounds write) in the WebKit engine shared across Apple's operating systems, fixed through improved state management. It is triggered when a device processes maliciously crafted web content, for example when a user loads an attacker-controlled web page or other web-rendered content, which is reflected in the required user-interaction element of the CVSS vector. Successful exploitation may lead to arbitrary code execution on the device. Essentially all Apple devices running versions of iOS, iPadOS, macOS Big Sur, tvOS, or watchOS earlier than the patched releases were affected, spanning the bulk of Apple's active installed base at the time. Apple reported the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; EPSS assigns a 3.7% probability of exploitation in the next 30 days (89th percentile). Do: Upgrade iPhones and iPads to iOS/iPadOS 14.5.1 (or iOS 12.5.3 on devices that cannot run 14.x), Macs to macOS Big Sur 11.3.1, Apple TVs to tvOS 14.6, and Apple Watches to watchOS 7.4.1. Because exploitation occurs through crafted web content, patching is the only reliable mitigation; use MDM or device inventory to confirm no managed Apple devices remain on pre-fix OS versions and treat any stragglers as actively at risk. | 8.8 | 4% | KEV |
| mass>1 billion active Apple devices (iOS/iPadOS/macOS/tvOS/watchOS installed base) | |
| CVE-2021-30713 | Privacy Preferences (TCC) Bypass in Apple macOS, Actively Exploited CVE-2021-30713 is a permissions/authorization flaw (CWE-862) in Apple macOS that allows a malicious application already running on a machine to bypass the user's Privacy preferences, which govern which apps may access protected user data such as files, camera, microphone, and other consent-protected resources. The flaw is triggered locally: a malicious app that a user has launched can silently circumvent the Privacy controls without the usual approval prompt. Successful exploitation grants the attacker access to user data that should have required explicit user consent, with high impact to confidentiality, integrity, and availability per its 7.8 CVSS score. Any Mac running a version of macOS prior to the macOS Big Sur 11.4 fix is affected. Apple acknowledged a report that the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; the EPSS score of 7.0% (94th percentile) further indicates meaningful near-term exploitation risk. Do: Upgrade affected Macs to macOS Big Sur 11.4 or later immediately, as this issue is listed in CISA's KEV catalog with active exploitation confirmed. Audit Macs for unknown or recently installed applications that accessed protected data (files, camera, microphone) without a consent prompt, and prioritize internet-facing and high-value endpoints. Since Apple shipped this fix alongside other actively exploited zero-days in the same release cycle, ensure devices are fully updated rather than partially patched. | 7.8 | 7% | KEV |
| masstens of millions of Macs (macOS runs on an installed base estimated at 100M+ devices, and Big Sur was the current release when the patch shipped) |
Full article597 words · extracted from securityaffairs.com · click to collapse

Apple has addressed three zero-day vulnerabilities in macOS and tvOS actively exploited in the wild by threat actors.
Apple has released security updates to address three zero-day vulnerabilities affecting macOS and tvOS which have been exploited in the wild. The macOS flaw has been exploited by the XCSSET malware to bypass security protections.
“Apple is aware of a report that this issue may have been actively exploited.” reads the security advisories published by Apple for the above issues.
The two zero-day flaws that impact WebKit on Apple TV 4K and Apple TV HD devices have been tracked as CVE-2021-30663 and CVE-2021-30665.
The CVE-2021-30663 zero-day is an integer overflow flaw that was addressed with improved input validation, the vulnerability was reported by an anonymous researcher.
The CVE-2021-30665 zero-day is a memory corruption issue that was addressed by the company with improved state management, the flaw was reported by yangkang (@dnpushme) &zerokeeper&bianliang of 360 ATA
The flaws could be exploited by attackers tricking the victims into visiting maliciously crafted web content.
The third zero-day, tracked as CVE-2021-30713, is a bypass of the Transparency Consent and Control (TCC) protections that was addressed with improved validation. The flaw impacts macOS Big Sur devices, it could be exploited by attackers to access data on disk gain additional permissions without user interaction.
Researchers from security firm Jamf reported that the flaw has been actively exploited by the XCSSET malware.
“In the latest macOS release (11.4), Apple patched a zero-day exploit (CVE-2021-30713) which bypassed the Transparency Consent and Control (TCC) framework. This is the system that controls what resources applications have access to, such as granting video collaboration software access to the webcam and microphone, in order to participate in virtual meetings.” reads the post published Jamf. “The exploit in question could allow an attacker to gain Full Disk Access, Screen Recording, or other permissions without requiring the user’s explicit consent — which is the default behavior. We, the members of the Jamf Protect detection team, discovered this bypass being actively exploited during additional analysis of the XCSSET malware, after noting a significant uptick of detected variants observed in the wild. The detection team noted that once installed on the victim’s system, XCSSET was using this bypass specifically for the purpose of taking screenshots of the user’s desktop without requiring additional permissions.”
The XCSSET malware was first spotted by Trend Micro last year [PDF] in a campaign targeting Mac users via infected Xcode projects, using two other zero-days to hijack the Safari web bro and inject malicious Javascript payloads.
XCSSET is a Mac malware that was discovered by Trend Micro in August 2020, it was spreading through Xcode projects and exploits two zero-day vulnerabilities to steal sensitive information from target systems and launch ransomware attacks.
According to Trend Micro, the threat allows stealing data associated with popular applications, including Evernote, Skype, Notes, QQ, WeChat, and Telegram. The malware also allows attackers to capture screenshots and exfiltrate stolen documents to the attackers’ server. The malware also implements ransomware behavior, it is able to encrypt files and display a ransom note.
The malware is also able to launch universal cross-site scripting (UXSS) attacks in an effort to inject JavaScript code into the browser while visiting specific websites and changing user’s browser experience. This behavior allows the malicious code to replace cryptocurrency addresses, and steal credentials for online services (amoCRM, Apple ID, Google, Paypal, SIPMarket, and Yandex) and payment card information from Apple Store.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, zero-day)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/118227/breaking-news/apple-zero-day-flaws.html