ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple backports iOS zero-day patch, adds Bluetooth tracker alert

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-23296CVE-2024-27852

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-23296
Kernel Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, watchOS, visionOS

CVE-2024-23296 is a memory corruption issue (CWE-787, out-of-bounds write) in the kernels of Apple's operating systems, addressed by Apple with improved validation in its March 2024 updates. Per Apple and the CVSS vector (AV:L/PR:L/UI:N), exploitation is local with low privileges and no user interaction: an attacker who has already gained arbitrary kernel read and write capability can use the flaw to bypass kernel memory protections, meaning it is typically used in an exploit chain after an initial kernel compromise. Successful abuse defeats hardened kernel memory restrictions, potentially giving the attacker broader control over the operating system and undermining kernel-level protections. Anyone running affected versions is exposed: iPhone/iPad on iOS/iPadOS prior to the 17.4 and 16.7.8 fixes, Macs prior to macOS Sonoma 14.4, Ventura 13.6.7 or Monterey 12.7.6, Apple TV prior to tvOS 17.4, Apple Watch prior to watchOS 10.4, and Vision Pro prior to visionOS 1.1. Apple has stated the issue may have been exploited in the wild, and CISA added it to the KEV catalog on 2024-03-06; no public proof-of-concept is known and ransomware use is unknown (EPSS 1.4%, 71st percentile).

Do: Patch immediately to iOS/iPadOS 17.4 (or 16.7.8 for devices staying on iOS 16), macOS Sonoma 14.4 / Ventura 13.6.7 / Monterey 12.7.6, tvOS 17.4, watchOS 10.4 and visionOS 1.1; no workaround is documented, and CISA's KEV required action mandates applying vendor fixes (or discontinuing use) for federal agencies. Because the flaw is used to bypass kernel memory protections after an attacker already has kernel read/write, also ensure devices are current on all other Apple kernel security updates and inventory for any Apple phones, tablets, Macs or TVs running older OS versions.

7.81% KEV
  • Apple iOS (iPhone OS) versions before 16.7.8 (16.x branch) and before 17.4 (17.x branch); fixed in iOS 16.7.8 and iOS 17.4
  • Apple iPadOS versions before 16.7.8 (16.x branch) and before 17.4 (17.x branch); fixed in iPadOS 16.7.8 and iPadOS 17.4
  • Apple macOS Monterey before 12.7.6, Ventura before 13.6.7, Sonoma before 14.4; fixed in macOS Monterey 12.7.6, Ventura 13.6.7 and Sonoma 14.4
  • +3 more
masshundreds of millions of devices (Apple's active installed base exceeds 2 billion devices; affected iOS/macOS/tvOS/watchOS versions were current for most users…
CVE-2024-27852
A privacy issue was addressed with improved client ID handling for alternative app marketplaces.

A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages.

NVD description · AI analysis pending
6.5<1%
  • apple ipados
  • apple iphone os
Full article445 words · extracted from helpnetsecurity.com · click to collapse

Apple has backported the patch for CVE-2024-23296 to the iOS 16 branch and has fixed a bug (CVE-2024-27852) in MarketplaceKit that may allow maliciously crafted webpages to distribute a script that tracks iOS users on other webpages.

The company has also added a new capability to iOS 17 that will alert users if an unknown Bluetooth tracker is “seen” moving with them.

Patched vulnerabilities

Apple released security updates for iOS and iPadOS, macOS, Safari, tvOS and watchOS on Monday.

The update for macOS Sonoma carries fixes for 22 vulnerabilities, the updates for macOS Ventura and Monterey just a handful.

The fix for the RTKit zero-day (CVE-2024-23296) – which has been patched in iOS and iPadOS 17.4, macOS Sonoma, watchOS, tvOS and visionOS in March 2024 after reports of in-the-wild exploitation – has been backported only to Ventura, iOS 16.7.8 and iPadOS 16.7.8 (for now).

Users running the iOS and iPadOS 17 branch can grab the latest update that fixes may different vulnerabilities. Among them is CVE-2024-27852, a bug in the MarketplaceKit that could allow sites to track iOS users.

In March 2023, Apple has introduced a new URI scheme in iOS 17.4 to allow EU users to install alternative (third-party) marketplace apps from developers’ websites. Unfortunately, faults in the scheme’s implementation allow it to be misused for cross-site tracking – as Talal Haj Bakry and Tommy Mysk of Mysk Inc. discovered.

The newest iOS/iPadOS update for the most recent branch will fix this vulnerability, but the researchers also warned users in the EU not to delete their alternative marketplace apps, because the update breaks alternative marketplace app re-installation.

“MarketplaceKit now generates a different client_id every time it is called. Now there’s no way for alternative marketplace developers to identify users who have already purchased the marketplace app,” they explained.

Warning users about Bluetooth tracking devices

Apple and Google announced that iPhones and Android 6.0+ devices will from now alert users to the presence of unknown Bluetooth tracking devices.

“If a user gets [an ‘(Item) Found Moving With You’ alert] on their iOS device, it means that someone else’s AirTag, Find My accessory, or other industry specification-compatible Bluetooth tracker is moving with them. It’s possible the tracker is attached to an item the user is borrowing, but if not, iPhone can view the tracker’s identifier, have the tracker play a sound to help locate it, and access instructions to disable it,” Apple explained.

“Bluetooth tag manufacturers including Chipolo, eufy, Jio, Motorola, and Pebblebee have committed that future tags will be compatible.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/05/14/ios-bluetooth-tracker-alert/