ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Apple Patches Two Zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-28206CVE-2023-28205

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28205
Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile).

Do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content.

8.827% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +3 more
mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari)
CVE-2023-28206
Out-of-Bounds Write in Apple IOSurfaceAccelerator Allows Kernel-Level Code Execution

Apple's IOSurfaceAccelerator component in iOS, iPadOS, and macOS contains an out-of-bounds write flaw (CWE-787). The bug is triggered by an application running locally on the device, which can corrupt memory in the component during a write past a buffer boundary. A successful exploit allows the app to execute arbitrary code with kernel privileges, giving it full control of the device beyond the normal app sandbox. Any user of an Apple iOS, iPadOS, or macOS device running an affected, unpatched version is exposed. The flaw was added to CISA KEV on 2023-04-10, confirming known in-the-wild exploitation; ransomware use is unknown, no public PoC is available, and EPSS assigns a 24.5% probability of exploitation within 30 days (98th percentile).

Do: Update all iPhones, iPads, and Macs to the latest iOS/iPadOS/macOS versions available as of April 2023, per CISA's required action and Apple's security advisories. Use MDM or patch-reporting tooling to inventory endpoints and confirm no devices remain on pre-patch builds. Because exploitation is confirmed in the wild and any local app can act as the trigger, patching is the primary mitigation and there is no dependable configuration workaround.

8.623% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's active iPhone/iPad/Mac installed base exceeds 1 billion)
Full article415 words · extracted from infosecurity-magazine.com · click to collapse

Apple released updates for two zero-day vulnerabilities that were used to attack iPhone, iPad and Mac devices.

“Apple is aware of a report that [these issues] may have been actively exploited,” the tech giant wrote in a security advisory published last Friday.

The first patched flaw (CVE-2023-28206) is an IOSurfaceAccelerator out-of-bounds write issue, potentially enabling an app to execute arbitrary code with kernel privileges. Apple said the issue was addressed with improved input validation. 

“The IOSurfaceAccelerator framework is used by many iOS and MacOS applications that require high-performance graphics processing, such as video editors, games and augmented reality applications,” explained Krishna Vishnubhotla, vice president of product strategy at Zimperium.

“Since IOSurfaceAccelerator provides low-level access to graphics hardware resources, exploiting a vulnerability in the framework could give an attacker the ability to manipulate graphics resources, intercept or modify data, or even cause the device to crash.”

The second vulnerability (CVE-2023-28205) is a WebKit use-after-free flaw that allows data corruption or arbitrary code execution when reusing freed memory. Apple said it fixed the bug with improved memory management.

“WebKit is a core software component of macOS and iOS, responsible for rendering web pages and executing JavaScript code in the Safari web browser and other applications that use WebKit,” said Vishnubhotla.

“Exploiting a vulnerability in WebKit could allow attackers to take control of the device’s web browsing capabilities and steal sensitive user data, such as login credentials and other personal information. It could also allow attackers to inject malicious code into web pages or launch phishing attacks to trick users into revealing sensitive information.”

Read more on Apple zero-days here: Apple Fixes Actively Exploited iPhone Zero-Day Vulnerability

Both vulnerabilities affect macOS Ventura 13.3.1 and iOS and iPadOS 16.4.1 devices. Apple credited Clément Lecigne of Google’s Threat Analysis Group and Donncha Ó Cearbhaill of Amnesty International’s Security Lab for their discovery.

“Apple is responding quickly here, which is good, especially with evidence that these vulnerabilities are being exploited in the wild,” commented Mike Parkin, Senior Technical Engineer at Vulcan Cyber.

“It is interesting that Amnesty International’s Security Lab was one of the organizations involved in finding and reporting the issue. While Apple hasn’t said much about the exploits, it seems likely, given the reporting and earlier history, that the exploits were deployed by state-level threat actors.”

The Apple advisory comes days after Google warned Android users of commercial spyware vendors exploiting zero-day flaws on mobile devices.

Editorial image credit: Omar Tursic / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apple-patches-two-exploited-zero/