ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes exploited zero-days: Update your devices! (CVE-2022-32894, CVE-2022-32893)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-2856
Intents Input Validation Flaw in Google Chrome for Android (CVE-2022-2856)

CVE-2022-2856 is an insufficient input validation flaw (CWE-20) in the Intents component of Google Chrome on Android. A remote attacker can trigger it by convincing a user to open a crafted HTML page, requiring no privileges beyond user interaction. On success, the attacker can make the victim's browser arbitrarily browse to a malicious, attacker-chosen website, an integrity impact (CVSS 3.1: 6.5, AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N). It affects Chrome on Android prior to 104.0.5112.101, and Fedora's chromium packages were also affected per the CPE data. The flaw is being exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-18, with headlines indicating it was the ninth actively exploited Chrome zero-day patched by Google in 2022.

Do: Update Chrome on Android to 104.0.5112.101 or later (check via Chrome's About page or the Play Store) and apply the updated Fedora chromium packages as they are released, per the CISA KEV required action. Verify fleet versions for managed Android/Chrome deployments and confirm no devices remain below 104.0.5112.101. Until patched, treat links from untrusted sources with caution since exploitation requires user interaction with a crafted page.

6.55% KEV PoC
  • google chrome Chrome on Android prior to 104.0.5112.101
  • fedoraproject fedora Fedora chromium builds prior to the 104.0.5112.101 fix (Fedora package version numbers not specified in the data)
mass≈1 billion+ Chrome-on-Android installations that were unpatched at the time of disclosure
CVE-2022-32893
+1 in the same advisory: …32894
Out-of-Bounds Write in Apple WebKit (iOS/macOS/Safari) Enables RCE

CVE-2022-32893 is an out-of-bounds write flaw (CWE-787) in Apple's WebKit browser engine, caused by insufficient bounds checking. It is triggered when a device processes maliciously crafted web content, meaning a user can be attacked simply by loading an attacker-controlled webpage. A successful exploit allows arbitrary code execution on the victim's device, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Affected users include anyone running iOS/iPadOS before 15.6.1, macOS Monterey before 12.5.1, or Safari before 15.6.1, as well as consumers of WebKitGTK and WPE WebKit shipped in Fedora and Debian. Apple confirmed the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-18; EPSS estimates a 9.9% probability of exploitation in the next 30 days (95th percentile), while no public PoC is known.

Do: Immediately update to iOS 15.6.1, iPadOS 15.6.1, macOS Monterey 12.5.1, and Safari 15.6.1; per vendor reporting, Apple also released updates for older iPhone models, and users of devices running the iOS 15.7 beta should apply 15.6.1. Fedora and Debian users should install the patched WebKitGTK/WPE WebKit packages from their distribution's advisories. Because exploitation requires only loading malicious web content, there is no reliable workaround — prioritize patching on all endpoints that browse web content, and treat unpatched Apple devices as actively targeted.

8.8
group max
10% KEV
  • Apple iPhone OS (iOS) all versions prior to 15.6.1
  • Apple iPadOS all versions prior to 15.6.1
  • Apple macOS Monterey prior to 12.5.1
  • +5 more
masshundreds of millions of devices (Apple's active iPhone/Mac installed base plus Safari/WebKit users)
Full article431 words · extracted from helpnetsecurity.com · click to collapse

Apple has released security updates for iOS, iPadOS, and macOS Monterey to fix CVE-2022-32894 and CVE-2022-32893, two code execution vulnerabilities exploited by attackers in the wild.

About the vulnerabilities (CVE-2022-32894, CVE-2022-32893)

CVE-2022-32894 is out-of-bounds write issue in the operating systems’ kernel that can be exploited by a malicious application to execute arbitrary code with kernel privileges (and take control over the entire system).

CVE-2022-32893 is out-of-bounds write issue in WebKit – Apple’s browser engine that powers its Safari web browser and all iOS web browsers – that can be triggered by the processing of maliciously crafted web content. It, as well, can lead to arbitrary code execution.

Both were reported by an anonymous researcher.

As per usual, Apple did not share details about the attacks that leverage the two zero-days, but it’s likely that the flaws are being exploited for targeted attacks.

Nevertheless, all users should implement the updates as soon as possible, by upgrading to:

  • iOS 15.6.1
  • iPadOS 15.6.
  • macOS 12.5.1 (updates for other supported macOS versions will likely follow at a later date)

Also fixed: A Chrome zero-day (CVE-2022-2856)

MacOS users who use Google Chrome and don’t have automatic updating switched on should also make sure to update that browser, because Google has pushed out a new version that fixes – among other vulnerabilities – CVE-2022-2856, an improper input validation bug affecting Chrome Intent.

Google says that the zero-day has been flagged by Ashley Shen and Christian Resell of Google Threat Analysis Group, and that it “is aware that an exploit for CVE-2022-2856 exists in the wild.”

“A Chrome Intent is a mechanism for triggering apps directly from a web page, in which data on the web page is fed into an external app that’s launched to process that data,” noted Paul Ducklin, Principal Research Scientist at Sophos.

“Google hasn’t provided any details of which apps, or what sort of data, could be maliciously manipulated by this bug (…) but the danger seems rather obvious if the known exploit involves silently feeding a local app with the sort of risky data that would normally be blocked on security grounds.”

Aside from a new version of Chrome for Mac, Google has also released new versions for Windows and Linux that fix the same vulnerabilities, and they will all be rolled out over the coming days/weeks.

UPDATE (August 19, 2022, 05:58 a.m. ET):

The WebKit flaw has been separately fixed in Safari 15.6.1.

UPDATE (September 1, 2022, 05:15 a.m. ET):

Apple has backported the patch for CVE-2022-32893 to iOS 12.5.6, and says that iOS 12 is not impacted by CVE-2022-32894.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/08/18/cve-2022-32894-cve-2022-32893-cve-2022-2856/