Spyware attack chain used previously unknown iPhone hardware feature, report says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-38606 | Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected. Do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines. | 5.5 | 3% | KEV |
| mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023) |
Full article520 words · extracted from therecord.media · click to collapse
Researchers at the cybersecurity firm Kaspersky said they discovered an obscure hardware feature that was likely exploited by hackers during previously reported spyware attacks on iPhone users. The announcement is an update to the researchers’ investigation of a campaign they named Operation Triangulation. Active since 2019, the hackers have been attacking targets by sending iMessages with malicious attachments and exploiting four zero-day security flaws, researchers said. The Russian government blamed this campaign on the U.S., alleging that it hacked “thousands of Apple phones” to spy on Russian diplomats. Apple has denied these claims, and Kaspersky has not attributed Operation Triangulation to any government or known hacking group Kaspersky’s new findings are related to a patched vulnerability tracked as CVE-2023-38606. Apple fixed this flaw in July, saying that the company “was aware of a report that this issue may have been actively exploited.” The researchers essentially said that the hackers used the obscure hardware feature to override hardware-based security intended to protect the kernel — the core part of an operating system that, among other things, provides a bridge between software and hardware. “If we try to describe this feature and how the attackers took advantage of it, it all comes down to this: they are able to write data to a certain physical address while bypassing the hardware-based memory protection by writing the data, destination address, and data hash to unknown hardware registers of the chip unused by the firmware,” the researchers said. According to researchers, the previously unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or it was included in the finished consumer version of the iPhone by mistake. “Because this feature is not used by the firmware, we have no idea how attackers would know how to use it,” the report said. In a comment to Recorded Future News, Apple’s spokesperson didn’t provide more details about Kaspersky’s new findings and instead sent the release notes for the patch to CVE-2023-38606. Relative to similar findings that Kaspersky has made over the years, “this is definitely the most sophisticated attack chain we have ever seen.” the researchers said. The company’s explanation of the attack chain includes 13 separate bullet points. According to Kaspersky, there are other unanswered questions surrounding the security flaw. “We do not know how the attackers learned to use this unknown hardware feature or what its original purpose was. Neither do we know if it was developed by Apple or it’s a third-party component,” researchers said. One thing that operations like this make clear is that “advanced hardware-based protections are useless in the face of a sophisticated attacker as long as there are hardware features that can bypass those protections,” Kaspersky said.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/operation-triangulation-iphone-spyware-unknown-hardware-feature