Apple patches FaceTime flaw and two exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-7286 | Out-of-Bounds Write Local Privilege Escalation in Apple iOS and macOS CVE-2019-7286 is a memory corruption flaw (an out-of-bounds write, CWE-787) in Apple's iOS and macOS that Apple addressed with improved input validation. It is triggered locally: the CVSS vector shows a local attack vector requiring user interaction, and an application that corrupts memory through the flaw may gain elevated privileges with high impact on confidentiality, integrity, and availability. Users running iPhones or iPads on iOS before 12.1.4, or macOS Mojave systems without the 10.14.3 Supplemental Update, are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), which indicates confirmed exploitation in the wild, and EPSS assigns it a 15.6% probability of exploitation within 30 days (97th percentile). No public proof-of-concept is catalogued, but defenders should treat it as actively exploited. Do: Update all iPhones and iPads to iOS 12.1.4 or later and apply the macOS Mojave 10.14.3 Supplemental Update (or a later macOS release) on Macs, per the CISA KEV required action. Inventory for devices that cannot run the fixed versions, restrict untrusted applications on them or retire them, since the flaw allows local apps to gain elevated privileges. Given the KEV listing, treat this as an actively exploited vulnerability and prioritize patching in any KEV-driven remediation program. | 7.8 | 16% | KEV |
| masshundreds of millions of Apple devices affected at the time of disclosure; current count of unpatched legacy devices unknown | |
| CVE-2019-7287 | Out-of-Bounds Write in Apple iOS Allows Kernel-Privilege Code Execution Apple iOS versions prior to 12.1.4 contain a memory corruption flaw — an out-of-bounds write (CWE-787) — which Apple fixed with improved input validation in iOS 12.1.4. Based on the flaw's CVSS scoring (local attack vector, user interaction required), it is triggered when a user opens or runs a malicious application on the device. A successful exploit lets that application execute arbitrary code with kernel privileges, giving the attacker full device control and access to all data on the phone. All Apple iPhones (iPhone OS) running iOS versions before 12.1.4 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), confirming known in-the-wild exploitation; EPSS currently assigns a 4.6% probability of exploitation activity within 30 days (91st percentile), no public proof-of-concept is cataloged, and ransomware use is unknown. Do: Apply Apple's update without delay, per CISA KEV's required action: update all iPhones and iOS devices to iOS 12.1.4 or later. Inventory your fleet for devices still running iOS 12.1.3 or earlier and prioritize patching them; on unpatched legacy devices, avoid opening untrusted applications until updated. Where hardware allows, move older devices off iOS 12 to a currently supported iOS release. | 7.8 | 5% | KEV |
| mass≈hundreds of millions of iPhone devices at time of disclosure (early 2019) |
Full article518 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The security patch squashes the widely-publicized FaceTime bug that allowed attackers to spy on others via audio and video.
An Apple security update released Thursday includes fixes for three vulnerabilities hackers already have exploited, leaving customers who fail to download the new software unprotected from known threats.
The security patch, iOS 12.1.4, squashes the widely-publicized FaceTime bug that allowed attackers to spy on others via audio and video. It also fixes two zero-day vulnerabilities that Ben Hawkes, a researcher on Google’s Project Zero security team, said had been exploited before the update was issued. The bugs, dubbed CVE-2019-7286 and CVE-2019-7287, would have allowed attackers to gain elevated privileges, and execute arbitrary code with kernel privileges, respectively.
Few details were immediately available about how and when those bugs were exploited, though prominent experts are encouraging users to update their phone as soon as possible. Users should visit the “Settings” page on their iPhone, then follow “General” to “Software Update.” Click “Download and Install.”
iOS user? Update to 12.1.4 now. It has some important zero days fixed as well as that Group FaceTime flaw. The zero days were found in the wild so it’s not just theoretical.
— Alan Woodward (@ProfWoodward) February 8, 2019
The update comes one week after New York Governor Andrew Cuomo and Attorney General Letitia James announced the state would investigate Apple’s handling of the FaceTime flaw. The software issue allowed iPhone users to see and listen to others before the recipient answered the video call.
A 14-year-old boy from Arizona first found the problem while chatting with friends while playing the video game “Fortnite.” The boy’s mother spent roughly a week trying to notify Apple about the issue, with little feedback.
The company now says it will compensate the family for an undisclosed amount for reporting the issue.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/iphone-update-facetime-flaw/