ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple Releases iOS and macOS Updates to Patch Actively Exploited 0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30807
Memory Corruption in Apple iOS, iPadOS, macOS, watchOS Allows Kernel Code Execution

A memory corruption flaw (out-of-bounds write, CWE-787) exists in Apple's IOMobileFrameBuffer component, a core graphics/frame-buffer interface shared across iOS, iPadOS, macOS, and watchOS. It is triggered by an application running on the device interacting with the frame buffer interface, which corrupts kernel memory. Successful exploitation may allow the application to execute arbitrary code with kernel privileges, giving the attacker full control of the device and bypassing normal app sandboxing. Any device running an unpatched version of iOS, iPadOS, macOS, or watchOS is affected, which spans essentially the entire Apple device fleet. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild, and EPSS assigns a 28.8% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Apple's current software updates for iOS, iPadOS, macOS, and watchOS on all managed devices per vendor instructions, prioritizing internet-facing and corporate-owned iPhones, iPads, and Macs. Use MDM/endpoint inventory to identify devices on outdated OS builds and verify patch compliance, noting CISA added this flaw to the KEV catalog on 2021-11-03 with required action to apply updates per vendor instructions.

7.829% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +1 more
mass≈1 billion+ active Apple devices (core OS component present across the iOS/iPadOS/macOS/watchOS install base); number actually exploited unknown
CVE-2021-30883
Kernel Memory Corruption Zero-Day in Apple iOS, iPadOS, macOS, tvOS, watchOS

CVE-2021-30883 is a memory corruption flaw (CWE-787, out-of-bounds write) in the kernel of Apple's iOS, iPadOS, macOS, tvOS, and watchOS, addressed with improved memory handling. It is triggered by a local application that mishandles memory, with the CVSS vector (AV:L, UI:R) indicating a user must run or interact with the malicious app. Successful exploitation allows arbitrary code execution with kernel privileges, giving an attacker full control over the affected device. All users of iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions earlier than the patched releases are affected. Apple acknowledged the issue may have been actively exploited in the wild, and CISA added it to the KEV catalog; related reporting indicates it was among 2021 zero-days developed commercially and sold to government clients.

Do: Upgrade iPhones and iPads to iOS/iPadOS 15.0.2 (or 14.8.1 for devices staying on iOS 14), Macs to macOS Monterey 12.0.1 or Big Sur 11.6.1, Apple TVs to tvOS 15.1, and Apple Watches to watchOS 8.1. As a CISA KEV entry, the required action is to apply updates per vendor instructions; inventory managed Apple devices and verify OS versions to confirm patching, prioritizing high-risk users who may have been targeted by commercial spyware.

7.815% KEV
  • Apple iPhone OS (iOS) prior to iOS 15.0.2 (iOS 15 line) and prior to iOS 14.8.1 (iOS 14 line)
  • Apple iPadOS prior to iPadOS 15.0.2 and prior to iPadOS 14.8.1
  • Apple macOS prior to macOS Monterey 12.0.1 and prior to macOS Big Sur 11.6.1
  • +2 more
mass≈1 billion+ Apple devices (iPhone/iPad/Mac/Apple TV/Apple Watch installed base running the affected OS versions)
CVE-2022-22584
+3 in the same advisory: …22593 …22578 …22585
A memory corruption issue was addressed with improved validation.

A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.3, iOS 15.3 and iPadOS 15.3, watchOS 8.4, macOS Monterey 12.2. Processing a maliciously crafted file may lead to arbitrary code execution.

NVD description · AI analysis pending
7.8
group max
2%
  • apple ipados
  • apple iphone os
  • apple macos
  • +1 more
CVE-2022-22587
Memory Corruption in Apple iOS, iPadOS, and macOS Allows Kernel-Privilege Code Execution

CVE-2022-22587 is a memory corruption flaw (CWE-787, out-of-bounds write) in Apple's operating systems that Apple addressed with improved input validation. It is triggered by a malicious application already running on a vulnerable device, which can exploit the corruption to execute arbitrary code with kernel privileges — the highest privilege level of the OS. All iPhones and iPads running iOS/iPadOS versions earlier than 15.3 and Macs running macOS Monterey earlier than 12.2 or Big Sur earlier than 11.6.3 are affected. Apple reported the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28; EPSS rates it at 11.6% probability of exploitation in the next 30 days (96th percentile). It was one of two actively exploited Apple zero-days patched in Apple's January 2022 emergency updates.

Do: Update iPhones and iPads to iOS/iPadOS 15.3 and Macs to macOS Monterey 12.2 or Big Sur 11.6.3 (or later). Inventory managed fleets for devices below these versions, since the flaw is exploited in the wild and CISA KEV requires applying vendor updates. Until devices are patched, limit exposure by avoiding installation of untrusted applications on vulnerable iPhones, iPads, and Macs.

9.812% KEV
  • Apple iPhone OS (iOS) iOS versions earlier than 15.3 (fixed in iOS 15.3)
  • Apple iPadOS iPadOS versions earlier than 15.3 (fixed in iPadOS 15.3)
  • Apple macOS Monterey macOS Monterey versions earlier than 12.2 (fixed in 12.2)
  • +1 more
mass>1 billion active Apple devices (all iPhones, iPads, and Macs below the fixed versions)
CVE-2022-22590
+1 in the same advisory: …22594
A use after free issue was addressed with improved memory management.

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.3 and iPadOS 15.3, watchOS 8.4, tvOS 15.3, Safari 15.3, macOS Monterey 12.2. Processing maliciously crafted web content may lead to arbitrary code execution.

NVD description · AI analysis pending
8.8
group max
2%
  • apple safari
  • apple ipados
  • apple iphone os
  • +1 more
CVE-2022-22591
A memory corruption issue was addressed with improved memory handling.

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges.

NVD description · AI analysis pending
7.81%
  • apple macos
Full article429 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 27, 2022

Apple on Wednesday released iOS 15.3 and macOS Monterey 12.2 with a fix for the privacy-defeating bug in Safari, as well as to contain a zero-day flaw, which it said has been exploited in the wild to break into its devices.

Tracked as CVE-2022-22587, the vulnerability relates to a memory corruption issue in the IOMobileFrameBuffer component that could be abused by a malicious application to execute arbitrary code with kernel privileges.

The iPhone maker said it's "aware of a report that this issue may have been actively exploited," adding it addressed the issue with improved input validation. It did not reveal the nature of the attacks, how widespread they are, or the identities of the threat actors exploiting them.

An anonymous researcher along with Meysam Firouzi and Siddharth Aeri have been credited with discovering and reporting the flaw.

CVE-2022-22587 is the third zero-day vulnerability discovered in IOMobileFrameBuffer in a span of six months after CVE-2021-30807 and CVE-2021-30883. In December 2021, Apple resolved four additional weaknesses in the kernel extension that's used to manage the screen framebuffer.

Also fixed by the tech giant is a recently disclosed vulnerability in Safari that stemmed from a faulty implementation of the IndexedDB API (CVE-2022-22594), which could be abused by a malicious website to track users' online activity in the web browser and even reveal their identity.

Other flaws of note include —

  • CVE-2022-22584 – A memory corruption issue in ColorSync that may lead to arbitrary code execution when processing a malicious crafted file
  • CVE-2022-22578 – A logic issue in Crash Reporter that could allow a malicious application to gain root privileges
  • CVE-2022-22585 – A path validation issue in iCloud that could be exploited by a rogue application to access a user's files
  • CVE-2022-22591 – A memory corruption issue in Intel Graphics Driver that could be abused by a malicious application to execute arbitrary code with kernel privileges
  • CVE-2022-22593 – A buffer overflow issue in Kernel that could be abused by a malicious application to execute arbitrary code with kernel privileges
  • CVE-2022-22590 – A use-after-free issue in WebKit that may lead to arbitrary code execution when processing maliciously crafted web content

The updates are available for iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, iPod touch (7th generation), and macOS devices running Big Sur, Catalina, and Monterey.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/01/apple-releases-ios-and-ipados-updates.html