ZeroHour
Security Affairspublished ()ingested @securityaffairs

Apple fixed 2 WebKit flaws exploited to target older iPhones

criticalVulnerability exploited in the wildimportance 60CVE-2021-30761CVE-2021-30762CVE-2021-30737

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30737
A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code.

A memory corruption issue in the ASN.1 decoder was addressed by removing the vulnerable code. This issue is fixed in tvOS 14.6, Security Update 2021-004 Mojave, iOS 14.6 and iPadOS 14.6, iOS 12.5.4, Security Update 2021-003 Catalina, macOS Big Sur 11.4, watchOS 7.5. Processing a maliciously crafted certificate may lead to arbitrary code execution.

NVD description · AI analysis pending
8.81%
  • apple ipados
  • apple iphone os
  • apple mac os x
  • +1 more
CVE-2021-30762
+1 in the same advisory: …30761
Use-After-Free in Apple iOS WebKit Enables RCE via Crafted Web Content

CVE-2021-30762 is a use-after-free memory-management flaw (CWE-416) in the WebKit browser engine used by Apple iOS. It is triggered when a vulnerable iPhone or iPad processes maliciously crafted web content, for example when a user browses to an attacker-controlled webpage. Successful exploitation allows arbitrary code execution with the privileges of the affected process, and the flaw scores 8.8 (high) on CVSS 3.1 (network vector, no privileges, user interaction required). Affected users are those running iOS versions that predate the fix, which Apple delivered in iOS 12.5.4 — an update targeting older devices still on the iOS 12 line. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns an 11.0% probability of exploitation within 30 days (96th percentile), though no public proof-of-concept is known.

Do: Update affected iPhones and iPads to iOS 12.5.4 or later, and users on newer iOS release lines should install the corresponding current Apple update, since the defect is in the shared WebKit component; verify the installed version via Settings > General > Software Update. Because exploitation occurs through web content and the flaw is on the CISA KEV list, patch promptly and avoid clicking links from untrusted sources until devices are updated.

8.811% KEV
  • Apple iPhone OS (iOS) iOS versions prior to 12.5.4 (fix delivered in iOS 12.5.4)
masshundreds of millions of iOS devices (WebKit runs in every iPhone; the iOS 12.5.4 fix targets the legacy-device population still on iOS 12 within Apple's 1B+…
Full article282 words · extracted from securityaffairs.com · click to collapse

Apple released an out-of-band iOS update for older iPhones and iPads and warned that threat actors are actively exploiting two flaws in WebKit.

Apple released an out-of-band iOS update ( iOS 12.5.4 patch) for older iPhones and iPad, the IT giant also warned that some vulnerabilities affecting its WebKit may have been actively exploited.

WebKit is a browser engine developed by Apple and primarily used in its Safari web browser, as well as all iOS web browsers.

Apple did not share details of the attacks that targeted older models of Apple iPhone devices.

The iOS 12.5.4 patch addressed at least three vulnerabilities that could be exploited by threat actors to execute arbitrary code on vulnerable devices.

Two of the addressed issues, tracked CVE-2021-30761 and CVE-2021-30762, are memory corruption and use-after-free issues respectively and reside in the WebKit rendering engine. The two flaws could be exploited by tricking owners of devices running iOS 12 into visiting specially crafted web content.

“Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.” reads the security advisory published by Apple.

The iOS 12.5.4 fixes the flaws in iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). Both issues were reported by an anonymous researcher.

The iOS 12.5.4 also addressed a memory corruption issue in the ASN.1 decoder tracked as CVE-2021-30737. The flaw can be exploited by processing a maliciously crafted certificate to lead to arbitrary code execution.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, iPhones)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/118970/security/apple-fixed-webkit-flaws.html