ZeroHour
The Recordpublished ()ingested

Google: Seven zero-days in 2021 developed commercially and sold to governments

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4344
Memory Corruption Flaw in Apple iOS, macOS, tvOS, and watchOS (Pre-2018 Releases)

CVE-2018-4344 is a memory corruption vulnerability (CWE-119) in Apple's operating systems that was fixed with improved memory handling in the Fall 2018 releases. It carries a local attack vector with user interaction required (CVSS AV:L/UI:R), meaning exploitation requires the victim to process attacker-supplied content, and successful exploitation yields high confidentiality, integrity, and availability impact, consistent with potential arbitrary code execution. Every user running versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 is affected, spanning iPhone/iPad, Mac, Apple TV, and Apple Watch. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2022-06-27, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. EPSS currently estimates a 2.9% probability of exploitation within 30 days (86th percentile).

Do: Upgrade affected devices to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 or later per Apple's instructions, as required by the CISA KEV listing. Inventory your fleet for Apple devices running outdated OS versions; for hardware that cannot run iOS 12, treat the device as permanently unpatched and replace or isolate it. Because the flaw is confirmed exploited in the wild and appears in KEV, prioritize these updates in patch cycles, particularly on user workstations and BYOD endpoints.

7.83% KEV
  • apple iPhone OS (iOS) on iPhone and iPad All versions prior to iOS 12
  • apple macOS (mac OS X) All versions prior to macOS Mojave 10.14
  • apple tvOS on Apple TV All versions prior to tvOS 12
  • +1 more
masshundreds of millions of Apple devices ran iOS/macOS/tvOS/watchOS versions below the 2018 fixes at disclosure, with an unknown but likely substantial share…
CVE-2019-8605
Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution

CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept.

Do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application.

7.818% KEV
  • apple iphone os (iOS) versions prior to iOS 12.3 (fixed in iOS 12.3)
  • apple mac os x (macOS Mojave) versions prior to macOS Mojave 10.14.5 (fixed in 10.14.5)
  • apple tvos versions prior to tvOS 12.3 (fixed in tvOS 12.3)
  • +1 more
masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact…
CVE-2020-3837
Memory Corruption in Apple iOS, macOS, tvOS, watchOS Enables Kernel-Level Code Execution

Apple patched an out-of-bounds write (CWE-787), a memory corruption flaw in kernel memory handling, across iOS/iPadOS, macOS Catalina, tvOS and watchOS. The flaw is triggered by a local application performing the faulty memory access, and the CVSS vector indicates user interaction (running the application) is required. A successful attacker can execute arbitrary code with kernel privileges, meaning full compromise of the affected device. Anyone running iPhone/iPad, Mac, Apple TV or Apple Watch software older than iOS/iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1 and watchOS 6.1.2 respectively is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), so exploitation has been observed in the wild, and EPSS assigns a 16.1% probability of exploitation within 30 days (97th percentile).

Do: Update all Apple endpoints to the fixed releases: iOS and iPadOS 13.3.1 or later, macOS Catalina 10.15.3 or later, tvOS 13.3.1 or later, and watchOS 6.1.2 or later; apply per vendor instructions to satisfy the KEV required action. Inventory managed and BYOD Apple devices for OS versions below these builds and prioritize patching, since the flaw is KEV-listed and mobile spyware campaigns targeting iPhones are active (e.g., LightSpy, though no confirmed link to this CVE is in the data). Until devices are patched, limit installing applications from untrusted sources, as triggering requires running a local application.

7.816% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 13.3.1
  • Apple iPadOS versions prior to iPadOS 13.3.1
  • Apple macOS (Catalina) versions prior to macOS Catalina 10.15.3
  • +2 more
masswell over 1 billion active Apple devices in the affected installed base (iPhone/iPad/Mac/Apple TV/Apple Watch)
CVE-2020-9907
Memory Corruption with Kernel Privileges in Apple iOS, iPadOS, and tvOS

Apple patched a kernel memory corruption flaw (CWE-787, out-of-bounds write) in iOS 13.6, iPadOS 13.6, and tvOS 13.4.8 by removing the vulnerable code. The flaw is triggered locally: an application running on the device (local attack vector, user interaction required per the CVSS scoring) can corrupt kernel memory and execute arbitrary code with kernel privileges. A successful attacker gains the highest privilege level on the device, effectively escalating from an application to full kernel control. Anyone running an iPhone, iPad, or Apple TV on versions earlier than iOS/iPadOS 13.6 or tvOS 13.4.8 is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-27, indicating exploitation in the wild, though no public proof-of-concept is known and EPSS estimates a roughly 3.9% chance of exploitation in the next 30 days.

Do: Upgrade iPhones and iPads to iOS/iPadOS 13.6 or later and Apple TV devices to tvOS 13.4.8 or later, per CISA's required action to apply vendor updates. Because the KEV listing confirms in-the-wild exploitation, prioritize patching and check current builds via Settings > General > Software Update. On unpatched devices, limit exposure by only installing trusted applications, since triggering the flaw requires an application running locally on the device.

7.84% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 13.6
  • Apple iPadOS versions prior to iPadOS 13.6
  • Apple tvOS versions prior to tvOS 13.4.8
masshundreds of millions of Apple devices at the time of disclosure (subset of the iOS/iPadOS installed base on pre-13.6 builds, plus legacy Apple TV units)
CVE-2021-30883
Kernel Memory Corruption Zero-Day in Apple iOS, iPadOS, macOS, tvOS, watchOS

CVE-2021-30883 is a memory corruption flaw (CWE-787, out-of-bounds write) in the kernel of Apple's iOS, iPadOS, macOS, tvOS, and watchOS, addressed with improved memory handling. It is triggered by a local application that mishandles memory, with the CVSS vector (AV:L, UI:R) indicating a user must run or interact with the malicious app. Successful exploitation allows arbitrary code execution with kernel privileges, giving an attacker full control over the affected device. All users of iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions earlier than the patched releases are affected. Apple acknowledged the issue may have been actively exploited in the wild, and CISA added it to the KEV catalog; related reporting indicates it was among 2021 zero-days developed commercially and sold to government clients.

Do: Upgrade iPhones and iPads to iOS/iPadOS 15.0.2 (or 14.8.1 for devices staying on iOS 14), Macs to macOS Monterey 12.0.1 or Big Sur 11.6.1, Apple TVs to tvOS 15.1, and Apple Watches to watchOS 8.1. As a CISA KEV entry, the required action is to apply updates per vendor instructions; inventory managed Apple devices and verify OS versions to confirm patching, prioritizing high-risk users who may have been targeted by commercial spyware.

7.815% KEV
  • Apple iPhone OS (iOS) prior to iOS 15.0.2 (iOS 15 line) and prior to iOS 14.8.1 (iOS 14 line)
  • Apple iPadOS prior to iPadOS 15.0.2 and prior to iPadOS 14.8.1
  • Apple macOS prior to macOS Monterey 12.0.1 and prior to macOS Big Sur 11.6.1
  • +2 more
mass≈1 billion+ Apple devices (iPhone/iPad/Mac/Apple TV/Apple Watch installed base running the affected OS versions)
CVE-2021-30983
Kernel Buffer Overflow in Apple iOS and iPadOS Enables Arbitrary Code Execution

CVE-2021-30983 is a buffer overflow (CWE-120) in Apple iOS and iPadOS, caused by improper memory handling, that was corrected in iOS 15.2 and iPadOS 15.2. It is triggered locally by an application running on the device (CVSS local attack vector with user interaction), so a user must run a malicious or compromised app for the flaw to be reached. Successful exploitation allows that application to execute arbitrary code with kernel privileges, giving the attacker near-complete control of the affected iPhone or iPad. Anyone using an iPhone or iPad running a version earlier than iOS/iPadOS 15.2 is affected. The vulnerability is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-27, with EPSS estimating a 2.9% probability of exploitation within 30 days; no public proof-of-concept is known.

Do: Upgrade all iPhones and iPads to iOS 15.2 or iPadOS 15.2 or later per Apple's instructions, as this is the required action in CISA's KEV catalog. Use MDM or device inventory to identify any devices still below 15.2 and prioritize them for patching; until updated, limit app installation from untrusted sources, since exploitation requires running an application on the device.

7.83% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 15.2
  • Apple iPadOS All versions prior to iPadOS 15.2
masshundreds of millions of iPhone/iPad devices (Apple's active installed base exceeds 1 billion; every device not yet updated to iOS/iPadOS 15.2 is affected)

Indicators of compromiseAll →

TypeIndicatorContext
domainfb-techsupport.come screenshot from one of the attacker controlled sites, www.fb-techsupport[.]com. (Google) Google said the applications are not available
Full article808 words · extracted from therecord.media · click to collapse

Google’s Threat Analysis Group (TAG) released a new report on Thursday chronicling an Italian spyware vendor selling technology used on victims in Italy and Kazakhstan.

The report mirrors another from cybersecurity company Lookout that was published last week covering “Hermit” – a brand of surveillanceware developed by spyware vendor RCS Labs and telecoms company Tykelab Srl.

The Google report examined the spyware from RCS Labs, noting that the Italian vendor “uses a combination of tactics, including atypical drive-by downloads as initial infection vectors, to target mobile users on both iOS and Android.”

Google TAG researchers Benoit Sevens and Clement Lecigne also touch on the wider commercial spyware industry, noting that Google continues to track the activities of vendors and recently testified at the EU Parliamentary hearing on “Big Tech and Spyware” about the work they’re doing “to monitor and disrupt this thriving industry.”

Today I had the opportunity to testify at the European Parliament @EP_PegaInquiry's hearing on "Big tech and Spyware".

This issue is something we are focused on addressing @Google and I wanted to take a moment and share some thoughts

— Charley Snyder (@charley_snyder_) June 14, 2022

“Seven of the nine zero-day vulnerabilities our Threat Analysis Group discovered in 2021 fall into this category: developed by commercial providers and sold to and used by government-backed actors,” Sevens and Lecigne explained. 

“TAG is actively tracking more than 30 vendors with varying levels of sophistication and public exposure selling exploits or surveillance capabilities to government-backed actors. Our findings underscore the extent to which commercial surveillance vendors have proliferated capabilities historically only used by governments with the technical expertise to develop and operationalize exploits. This makes the Internet less safe and threatens the trust on which users depend.”

iOS and Android versions

Like the Lookout report, Google found that RCS Labs’ spyware generally originates from a unique link sent to a victim. Once the link is clicked, the victim is asked to download and install a malicious app.

They found evidence that victims had both Android or iOS devices. Surprisingly, Google noted that they believe the actors behind the campaigns at times worked with victims' internet service providers to “disable the target’s mobile data connectivity.”

“Once disabled, the attacker would send a malicious link via SMS asking the target to install an application to recover their data connectivity,” the researchers said.  

“We believe this is the reason why most of the applications masqueraded as mobile carrier applications. When ISP involvement is not possible, applications are masqueraded as messaging applications.”

An example screenshot from one of the attacker controlled sites, www.fb-techsupport[.]com. (Google)

Google said the applications are not available on the App Store but are signed with a certificate from a company named 3-1 Mobile SRL, which “satisfies all of the iOS code signing requirements on any iOS devices because the company was enrolled in the Apple Developer Enterprise Program.”

The app analyzed by Sevens and Lecigne contained exploits for six CVEs – CVE-2018-4344, CVE-2019-8605, CVE-2020-3837, CVE-2020-9907, CVE-2021-30883 and CVE-2021-30983.

“All exploits used before 2021 are based on public exploits written by different jailbreaking communities,” the researchers said. 

“At the time of discovery, we believe CVE-2021-30883 and CVE-2021-30983 were two 0-day exploits. In collaboration with TAG, Project Zero has published the technical analysis of CVE-2021-30983.”

For Android devices, the app disguises itself as a legitimate Samsung application via its icon. But Google confirmed it was never available in the Google Play app store. 

Google said it implemented changes to Google Play Protect and disabled Firebase projects used as C2 in the campaign as a way to protect its users. It also warned all of the Android device victims of the spyware campaign. 

The report notes that the spyware industry is currently “thriving and growing at a significant rate” and is being fueled by numerous governments incapable of developing these kinds of capabilities themselves.

The industry is being exploited by governments “for purposes antithetical to democratic values: targeting dissidents, journalists, human rights workers and opposition party politicians.”

Sevens and Lecigne added that it is also concerning vendors like RCS Labs are “stockpiling zero-day vulnerabilities in secret” and noted that this is even more problematic considering a number of spyware vendors have been compromised over the past ten years, “raising the specter that their stockpiles can be released publicly without warning.”

“Tackling the harmful practices of the commercial surveillance industry will require a robust, comprehensive approach that includes cooperation among threat intelligence teams, network defenders, academic researchers, governments and technology platforms,” the two researchers said. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-seven-zero-days-in-2021-developed-commercially-and-sold-to-governments