Apple Rolls Out Security Patches for Actively Exploited iOS Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41993 | WebKit Code Execution Flaw in Apple iOS, iPadOS, macOS, and Safari Apple's WebKit engine, which renders web content for Safari and for essentially all HTML processing on iOS, iPadOS, and macOS, contains a flaw that leads to code execution when processing maliciously crafted web content. It is triggered when a user's browser or embedded web view loads attacker-controlled web content, so simply visiting a hostile page can be enough. Successful exploitation could allow arbitrary code execution within the affected application's context, a common stepping stone to broader device compromise. All users of Apple iOS, iPadOS, macOS, and Safari are potentially affected, as are users of non-Apple products that rely on WebKit for HTML processing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known. Do: Apply Apple's latest security updates for iOS, iPadOS, macOS, and Safari that patch WebKit, following the vendor instructions referenced by the CISA KEV entry, and treat unpatched WebKit builds as actively exploited. Until systems are patched, restrict exposure to untrusted web content (e.g., limit browsing and in-app web views to trusted sites for high-risk users). Also inventory any non-Apple applications or HTML-processing components in your environment that bundle WebKit and update them as their maintainers ship fixes. | 8.8 group max | 29% | KEV |
| mass1+ billion devices/users (WebKit ships in Safari and all web-content rendering on iOS, iPadOS, and macOS) | |
| CVE-2023-42824 | Kernel Privilege Escalation in Apple iOS and iPadOS (Actively Exploited) CVE-2023-42824 is a privilege escalation vulnerability in the kernel of Apple's iOS and iPadOS, addressed with improved checks in iOS 16.7.1 and iPadOS 16.7.1. It is triggered locally: an attacker who can already run code on the device (for example via a malicious app or as one stage of a chained attack) exploits the flaw to elevate privileges. Successful exploitation grants kernel-level privilege, with high confidentiality, integrity, and availability impact, meaning near-full control of the affected device. Any iPhone or iPad running iOS/iPadOS versions prior to 16.7.1 is affected, and Apple reported the issue was being actively exploited against iOS versions before 16.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-05 with no public PoC listed, making patching urgent. Do: Update affected iPhones and iPads to iOS 16.7.1 / iPadOS 16.7.1 or later (any subsequent iOS release includes the fix), and verify device versions via Settings > General > Software Update. There is no indicated workaround, so prioritize patching for high-risk users (executives, admins, journalists), since local kernel elevation bugs of this kind are commonly chained with remote code execution or sandbox-escape exploits. Per CISA's required action, apply the vendor updates promptly or restrict use of unpatched devices. | 7.8 | <1% | KEV |
| masshundreds of millions of consumer devices (Apple's active iPhone/iPad installed base exceeds 1 billion) | |
| CVE-2023-5217 | Heap Buffer Overflow in Google Chromium libvpx (CVE-2023-5217) Added to CISA KEV CVE-2023-5217 is a heap buffer overflow (CWE-787) in the VP8 encoding path of libvpx, the open-source video codec library bundled with Google's Chromium/Chrome browser. A remote attacker can trigger the flaw by luring a user to a crafted HTML page whose web content invokes the vulnerable VP8 encoding code, corrupting the heap and potentially achieving code execution in the affected browser. Anyone running Google Chrome/Chromium — or other browsers and software that embed libvpx, as CISA notes the library's use is 'not limited to Google Chrome' — is affected. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-10-02 (ransomware association: unknown), though no public proof-of-concept is available and a CVSS score has not been published; EPSS puts the 30-day exploitation probability at 49% (99th percentile). Defenders should treat this as an actively exploited browser vulnerability requiring prompt patching. Do: Update Chrome/Chromium to the vendor release that fixes CVE-2023-5217 — Google shipped the fix with its late-September 2023 stable-channel security update, so verify the exact build number in Google's advisory (it is not specified in the source data). Also patch any other products bundling libvpx (other browsers, media/ffmpeg-based tooling) per vendor instructions, and ensure KEV compliance by applying the required mitigations or discontinuing use of affected builds by the CISA deadline. | 8.8 | 49% | KEV PoC |
| masson the order of 1–3+ billion users/devices (Chrome's global installed base; roughly two-thirds desktop browser market share) |
Full article503 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 05, 2023Zero Day / Vulnerability
Apple on Wednesday rolled out security patches to address a new zero-day flaw in iOS and iPadOS that it said has come under active exploitation in the wild.
Tracked as CVE-2023-42824, the kernel vulnerability could be abused by a local attacker to elevate their privileges. The iPhone maker said it addressed the problem with improved checks.
"Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6," the company noted in a terse advisory.
While additional details about the nature of the attacks and the identity of the threat actors perpetrating them are currently unknown, successful exploitation likely hinges on an attacker already obtaining an initial foothold by some other means.
Apple's latest update also resolves CVE-2023-5217 impacting the WebRTC component, which Google last week described as a heap-based buffer overflow in the VP8 compression format in libvpx.
The patches, iOS 17.0.3 and iPadOS 17.0.3, are available for the following devices -
- iPhone XS and later
- iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
With the new development, Apple has addressed a total of 17 actively exploited zero-days in its software since the start of the year.
It also arrives two weeks after Cupertino rolled out fixes to resolve three issues (CVE-2023-41991, CVE-2023-41992, and CVE-2023-41993), all of which are said to have been abused by an Israeli spyware vendor named Cytrox to deliver the Predator malware onto the iPhone belonging to former Egyptian member of parliament Ahmed Eltantawy earlier this year.
A point worth noting here is that CVE-2023-41992 also refers to a shortcoming in the kernel that allows local attackers to achieve privilege escalation.
It's not immediately clear if the two flaws have any connection with one another, and if CVE-2023-42824 is a patch bypass for CVE-2023-41992.
Sekoia, in a recent analysis, said it had, in December 2021, found infrastructure similarities between customers of Cytrox (aka Lycantrox) and another commercial spyware company called Candiru (aka Karkadann), likely due to them using both spyware technologies.
"The infrastructure used by the Lycantrox consists of VPS hosted in several autonomous systems," the French cybersecurity firm said, with each customer appearing to run their own instances of VPS and manage their own domain names related to it.
Users who are at risk of being targeted are recommended to enable Lockdown Mode to reduce exposure to mercenary spyware exploits.
Apple Expands Patches to Older Devices
Apple on October 10, 2023, backported patches for CVE-2023-42824 and CVE-2023-5217 to older devices, such as iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/apple-rolls-out-security-patches-for.html