ZeroHour
The Recordpublished ()ingested

macOS zero-day deployed via Hong Kong pro

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1789
Type Confusion RCE in Apple WebKit (iOS, macOS, Safari, tvOS, watchOS)

CVE-2021-1789 is a type confusion flaw (CWE-843) in the WebKit engine that powers Safari and web views across Apple's platforms, fixed through improved state handling. An attacker triggers it by getting a victim to open or view maliciously crafted web content, for example via a crafted link in an email or a compromised webpage. Successful exploitation leads to arbitrary code execution in the context of the application rendering the content, and the CVSS 3.1 score of 8.8 reflects high confidentiality, integrity and availability impact with network attack vector and user interaction required. Everyone running affected Apple software below the February 2021 patch levels is exposed — iOS/iPadOS before 14.4, macOS Big Sur before 11.2, macOS Catalina/Mojave without Security Update 2021-001, tvOS before 14.4, watchOS before 7.3, and Safari before 14.0.3 — as well as WebKitGTK users on Fedora per the CPE data. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-05-04) and was used as a macOS zero-day in watering-hole attacks on Hong Kong pro-democracy users, deploying the DazzleSpy backdoor; EPSS estimates a 14.5% chance of exploitation in the next 30 days.

Do: Update to iOS/iPadOS 14.4, macOS Big Sur 11.2 (or apply Security Update 2021-001 on Catalina/Mojave), Safari 14.0.3, tvOS 14.4 and watchOS 7.3; on Fedora, apply the available webkitgtk package update. Because this flaw is in CISA KEV and used in targeted watering-hole attacks, prioritize patching internet-facing and high-risk user fleets. Confirm inventory shows no Apple devices below these patch levels and that users are not relying on outdated Safari builds on unsupported macOS versions.

8.814% KEV
  • apple iOS prior to 14.4
  • apple iPadOS prior to 14.4
  • apple macOS Big Sur prior to 11.2
  • +7 more
masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch) plus WebKitGTK-based Linux browsers/apps
CVE-2021-30869
Type Confusion in Apple iOS, iPadOS and macOS Allows Kernel Code Execution

CVE-2021-30869 is a type confusion flaw (CWE-843) in the kernel of Apple's iOS, iPadOS, and macOS operating systems, addressed with improved state handling. It is triggered locally when a user runs a malicious application, which can then leverage the memory-type confusion to escape the app sandbox context. Successful exploitation gives the attacker arbitrary code execution with kernel privileges, effectively full control of the device. Users of iPhone, iPad, and Mac running versions released before the January 2021 fixes are affected. Apple has confirmed exploits exist in the wild, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and news reporting linked exploitation to targeted attacks against macOS users in Hong Kong.

Do: Upgrade to iOS 14.4 (or iOS 12.5.5 for older devices), iPadOS 14.4, or macOS Big Sur 11.2, and apply Security Update 2021-001 Catalina or Security Update 2021-001 Mojave (Security Update 2021-006 Catalina also addresses the issue) on Macs. Because exploitation requires running a malicious application, remove untrusted apps and warn users against installing software from unverified sources while patching. This flaw is on the CISA KEV list, so federal and KEV-committed organizations must apply the updates per vendor instructions; no public proof-of-concept is known.

7.84% KEV
  • Apple iPhone OS (iOS) iOS versions prior to 14.4; iOS 12.x prior to 12.5.5
  • Apple iPadOS iPadOS versions prior to 14.4
  • Apple macOS Big Sur macOS Big Sur versions prior to 11.2
  • +2 more
masshundreds of millions of devices (Apple's active installed base of iPhones, iPads, and Macs is on the order of 1 billion devices, and pre-patch OS versions were…
Full article402 words · extracted from therecord.media · click to collapse

A suspected state-sponsored threat actor has used Hong Kong pro-democracy news sites to deploy a macOS zero-day exploit chain that installed a backdoor on visitors' computers.

  • The attacks have been taking place since at least August 2021.
  • The exploit chain combined a remote code execution bug in WebKit (CVE-2021-1789, patched on Jan 5, 2021) with a local privilege escalation in the XNU kernel component (CVE-2021-30869, later patched on Sept 23, 2021).
  • The attackers used the exploit chain to gain root access to the macOS operating system and download and install a malware strain named MACMA or OSX.CDDS.

This never-before-seen malware contained features specific to both backdoor and spyware strains and gave attackers the ability to:

  • Fingerprint devices for later identification
  • Take screenshots of the screen
  • Log keystrokes
  • Record local audio
  • Download or upload files
  • Execute terminal commands.

The attacks using this macOS zero-day were first detected by the Google Threat Analysis Group, which reported the zero-day vulnerability to Apple to have it patched.

The Google team has released a report today detailing what they saw in the attacks. Additional details from this report also include:

  • iOS users were also targeted, but using a different exploit chain which Google TAG wasn't able to recover in full.
  • The zero-day exploit was actually public, having been presented by the Pangu Lab research team in a talk at zer0con21 in April 2021 and Mobile Security Conference (MOSEC) in July 2021, before being used in attacks in August.
  • It's unclear if Pangu Lab reported the vulnerability to Apple or if Apple was tardy in patching the bug, as usual, allowing the threat actors to mount their attacks based on the public information.
  • Google TAG described the threat actor behind the attacks as a "well-resourced group, likely state backed, with access to their own software engineering team based on the quality of the payload code."
  • Google did not attribute the attacks to any country nor any threat actor they saw in previous operations.

Besides Google's report, macOS security researcher Patrick Wardle has also published an independent analysis of the MACMA (OSX.CDDS) malware on his blog, going into details beyond Google's short analysis.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/macos-zero-day-deployed-via-hong-kong-pro-democracy-news-sites