macOS Zero-Day exploited in watering hole attacks on users in Hong Kong
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-8506 | Type Confusion in Apple WebKit (Safari, iOS, iCloud, iTunes) Allows Code Execution CVE-2019-8506 is a type confusion flaw (CWE-843) in the web content processing engine shared by Apple's Safari browser and the iOS, tvOS, and watchOS operating systems, as well as iTunes and iCloud for Windows. It is triggered when a user processes maliciously crafted web content, such as by visiting an attacker-controlled webpage. Successful exploitation may allow the attacker to execute arbitrary code on the affected device or desktop. Anyone running Safari or iOS/tvOS versions before 12.2, watchOS before 5.2, or iTunes/iCloud for Windows before the fixed 12.9.4/7.11 releases is affected, and Red Hat Enterprise Linux (Desktop, Server, Workstation) is also listed among affected products in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-04, indicating known exploitation in the wild, though no public PoC is available and ransomware use is unknown. Do: Upgrade affected Apple software to the fixed releases: iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud for Windows 7.11, or later versions. Inventory Windows endpoints for iTunes and iCloud installations, which are frequently overlooked, and update or remove them. Red Hat Enterprise Linux users should apply Red Hat's updates addressing this CVE, and because this is a CISA KEV entry, patch per vendor instructions promptly. | 8.8 | 18% | KEV |
| mass≈1 billion+ users/devices | |
| CVE-2021-1789 | Type Confusion RCE in Apple WebKit (iOS, macOS, Safari, tvOS, watchOS) CVE-2021-1789 is a type confusion flaw (CWE-843) in the WebKit engine that powers Safari and web views across Apple's platforms, fixed through improved state handling. An attacker triggers it by getting a victim to open or view maliciously crafted web content, for example via a crafted link in an email or a compromised webpage. Successful exploitation leads to arbitrary code execution in the context of the application rendering the content, and the CVSS 3.1 score of 8.8 reflects high confidentiality, integrity and availability impact with network attack vector and user interaction required. Everyone running affected Apple software below the February 2021 patch levels is exposed — iOS/iPadOS before 14.4, macOS Big Sur before 11.2, macOS Catalina/Mojave without Security Update 2021-001, tvOS before 14.4, watchOS before 7.3, and Safari before 14.0.3 — as well as WebKitGTK users on Fedora per the CPE data. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-05-04) and was used as a macOS zero-day in watering-hole attacks on Hong Kong pro-democracy users, deploying the DazzleSpy backdoor; EPSS estimates a 14.5% chance of exploitation in the next 30 days. Do: Update to iOS/iPadOS 14.4, macOS Big Sur 11.2 (or apply Security Update 2021-001 on Catalina/Mojave), Safari 14.0.3, tvOS 14.4 and watchOS 7.3; on Fedora, apply the available webkitgtk package update. Because this flaw is in CISA KEV and used in targeted watering-hole attacks, prioritize patching internet-facing and high-risk user fleets. Confirm inventory shows no Apple devices below these patch levels and that users are not relying on outdated Safari builds on unsupported macOS versions. | 8.8 | 14% | KEV |
| masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch) plus WebKitGTK-based Linux browsers/apps | |
| CVE-2021-30869 | Type Confusion in Apple iOS, iPadOS and macOS Allows Kernel Code Execution CVE-2021-30869 is a type confusion flaw (CWE-843) in the kernel of Apple's iOS, iPadOS, and macOS operating systems, addressed with improved state handling. It is triggered locally when a user runs a malicious application, which can then leverage the memory-type confusion to escape the app sandbox context. Successful exploitation gives the attacker arbitrary code execution with kernel privileges, effectively full control of the device. Users of iPhone, iPad, and Mac running versions released before the January 2021 fixes are affected. Apple has confirmed exploits exist in the wild, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and news reporting linked exploitation to targeted attacks against macOS users in Hong Kong. Do: Upgrade to iOS 14.4 (or iOS 12.5.5 for older devices), iPadOS 14.4, or macOS Big Sur 11.2, and apply Security Update 2021-001 Catalina or Security Update 2021-001 Mojave (Security Update 2021-006 Catalina also addresses the issue) on Macs. Because exploitation requires running a malicious application, remove untrusted apps and warn users against installing software from unverified sources while patching. This flaw is on the CISA KEV list, so federal and KEV-committed organizations must apply the updates per vendor instructions; no public proof-of-concept is known. | 7.8 | 4% | KEV |
| masshundreds of millions of devices (Apple's active installed base of iPhones, iPads, and Macs is on the order of 1 billion devices, and pre-patch OS versions were… |
Full article506 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 12, 2021

Google revealed that threat actors recently exploited a zero-day vulnerability in macOS to deliver malware to users in Hong Kong.
Google TAG researchers discovered that threat actors leveraged a zero-day vulnerability in macOS in a watering hole campaign aimed at delivering malware to users in Hong Kong. The attackers exploited a XNU privilege escalation vulnerability (CVE-2021-30869) unpatched in macOS Catalina
The watering hole campaign targeted websites of a media outlet and important pro-democracy labor and political group. The researchers discovered that attackers deployed on the sites hosted two iframes that were used to serve iOS and macOS exploits to the visitors.
The experts believe that the attack was orchestrated by a nation-state actor, but did not attribute the campaign to a specific APT group.
The attack was discovered in late August, the nature of the targets and the level of sophistication of the attack suggests the involvement of a China-linked threat actor.
“To protect our users, TAG routinely hunts for 0-day vulnerabilities exploited in-the-wild. In late August 2021, TAG discovered watering hole attacks targeting visitors to Hong Kong websites for a media outlet and a prominent pro-democracy labor and political group. The watering hole served an XNU privilege escalation vulnerability (CVE-2021-30869) unpatched in macOS Catalina, which led to the installation of a previously unreported backdoor.” reads the analysis published by Google. “As is our policy, we quickly reported this 0-day to the vendor (Apple) and a patch was released to protect users from these attacks.”
The iOS exploit chain used a framework based on Ironsquirrel to encrypt exploits delivered to the visitor’s browser. Google researchers pointed out that they were not able to retrieve the complete iOS chain. Evidence collected demonstrated that attackers exploited the CVE-2019-8506 flaw to execute malicious code in Safari.
The macOS exploits were different from the iOS ones. Threat actors set up a landing page containing a simple HTML page loading two scripts, one for Capstone.js and another for the exploit chain.
The exploit chain used in this case combined the CVE-2021-1789 RCE in WebKit and a 0-day local privilege escalation in XNU (CVE-2021-30869) patched by Apple in Sept.
The analysis of the macOS exploits revealed the presence of a parameter used by the threat actors to record the number of exploitation attempts, this parameter had a value of roughly 200 at the time of its discovery.
The watering hole attack allowed the attackers to deliver a Mac malware (OSX.CDDS) that implements surveillance capabilities, such as capturing keystrokes, taking screenshots, fingerprinting compromised devices, uploading/downloading files, executing terminal commands, and recording audio.
It is interesting to note that the malware had a zero detection rate on VirusTotal malware analysis service at the time of analysis, a circumstance that demonstrates the level of sophistication of the attack.
Google TAG researchers shared Indicators of Compromise (IoCs) for these attacks.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, watering hole)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/124513/malware/macos-zero-day-watering-hole-hong-kong.html