ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Apple Issues Patch for Critical Zero-Day in iPhones, Macs

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-23222CVE-2023-42916CVE-2023-42917

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-42917
+1 in the same advisory: …42916
WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution

CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).

Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.

8.8
group max
9% KEV
  • apple iphone os (iOS) versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1
  • apple ipados versions prior to iPadOS 17.1.2
  • apple macos (Sonoma) versions prior to macOS Sonoma 14.1.2
  • +4 more
masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base)
CVE-2024-23222
Apple WebKit Type Confusion Enables Arbitrary Code Execution Across iOS, macOS, tvOS

CVE-2024-23222 is a type confusion flaw (CWE-843) in Apple's WebKit engine that allows arbitrary code execution when a device processes maliciously crafted web content, for example when a user is lured into loading attacker-controlled web pages in Safari or another WebKit-based view (the CVSS vector confirms user interaction is required). It affects a broad slice of the Apple ecosystem: Safari, iPhone OS/iPadOS on the iOS 15, 16 and 17 branches, macOS Monterey/Ventura/Sonoma, tvOS and visionOS, prior to the January 22, 2024 fixes. A successful attacker gains code execution on the target device with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). The flaw was fixed in Safari 17.3, iOS/iPadOS 17.3, and backported to iOS/iPadOS 15.8.7 and 16.7.5 for devices that cannot upgrade to iOS 17, plus macOS Monterey 12.7.3, Ventura 13.6.4, Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2024-01-23, one day after the fixes shipped, and is associated with the Coruna exploit kit, which reportedly chains multiple exploits to target iOS devices including older versions.

Do: Update all affected devices to Safari 17.3, iOS/iPadOS 17.3 (or the iOS/iPadOS 15.8.7 and 16.7.5 backports for devices that cannot run 17), macOS Monterey 12.7.3, macOS Ventura 13.6.4, macOS Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Prioritize endpoints used for web browsing and mobile users, since exploitation only requires a user to process crafted web content. The CISA KEV listing (added 2024-01-23) makes applying these vendor updates mandatory under the KEV required action, so verify fleet versions and confirm no devices remain on pre-patch builds.

8.811% KEV
  • apple Safari Versions prior to Safari 17.3 (fixed in 17.3)
  • apple iPhone OS (iOS) Versions prior to iOS 17.3; fixes backported in iOS 15.8.7 and iOS 16.7.5 for devices that cannot run iOS 17.3
  • apple iPadOS Versions prior to iPadOS 17.3; fixes backported in iPadOS 15.8.7 and iPadOS 16.7.5
  • +3 more
massover 1 billion active Apple devices (effectively Apple's entire unpatched iPhone/iPad/Mac/Apple TV fleet)
Full article419 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 23, 2024Vulnerability / Device Security

Apple on Monday released security updates for iOS, iPadOS, macOS, tvOS, and Safari web browser to address a zero-day flaw that has come under active exploitation in the wild.

The issue, tracked as CVE-2024-23222, is a type confusion bug in the WebKit browser engine that could be exploited by a threat actor to achieve arbitrary code execution when processing maliciously crafted web content. The tech giant said the problem was fixed with improved checks.

Type confusion vulnerabilities, in general, could be weaponized to perform out-of-bounds memory access, or lead to a crash and arbitrary code execution.

In a terse advisory, Apple acknowledged it's "aware of a report that this issue may have been exploited," but did not share any other specifics about the nature of attacks or the threat actors leveraging the shortcoming.

The updates are available for the following devices and operating systems -

  • iOS 17.3 and iPadOS 17.3 - iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
  • iOS 16.7.5 and iPadOS 16.7.5 - iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
  • macOS Sonoma 14.3 - Macs running macOS Sonoma
  • macOS Ventura 13.6.4 - Macs running macOS Ventura
  • macOS Monterey 12.7.3 - Macs running macOS Monterey
  • tvOS 17.3 - Apple TV HD and Apple TV 4K (all models)
  • Safari 17.3 - Macs running macOS Monterey and macOS Ventura

The development marks the first actively exploited zero-day vulnerability to be patched by Apple this year. Last year, the iPhone maker had addressed 20 zero-days that have been employed in real-world attacks.

In addition, Apple has backported fixes for CVE-2023-42916 and CVE-2023-42917 – patches for which were first released in December 2023 – to older devices -

  • iOS 15.8.1 and iPadOS 15.8.1 - iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

The disclosure also follows a report that Chinese authorities revealed that they have used previously known vulnerabilities in Apple's AirDrop functionality to help law enforcement to identify senders of inappropriate content, using a technique based on rainbow tables.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/01/apple-issues-patch-for-critical-zero.html