ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-14315
In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted dev

In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

NVD description · AI analysis pending
7.5<1%
  • apple iphone os
CVE-2017-6975
Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point.

Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom firmware functions, there is a separate CVE ID for the operating-system behavior.

NVD description · AI analysis pending
6.8<1% PoC
  • apple iphone os
CVE-2017-9417
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

NVD description · AI analysis pending
9.864%
  • broadcom bcm43xx wi-fi chipset firmware
CVE-2019-8617
+3 in the same advisory: …8585 …8620 …8626
An access issue was addressed with additional sandbox restrictions.

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 12.3. A sandboxed process may be able to circumvent sandbox restrictions.

NVD description · AI analysis pending
9.6
group max
1%
  • apple iphone os
CVE-2019-8634
+1 in the same advisory: …8589
An authentication issue was addressed with improved state management.

An authentication issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5. A user may be unexpectedly logged in to another user’s account.

NVD description · AI analysis pending
8.8
group max
<1%
  • apple mac os x
CVE-2019-8592
A memory corruption issue was addressed with improved input validation.

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, tvOS 12.3, watchOS 5.2.1, tvOS 13, macOS Catalina 10.15.1, Security Update 2019-001, and Security Update 2019-006, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3, iOS 13. Playing a malicious audio file may lead to arbitrary code execution.

NVD description · AI analysis pending
7.81%
  • apple iphone os
  • apple mac os x
  • apple tvos
  • +1 more
CVE-2019-8605
Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution

CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept.

Do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application.

7.818% KEV
  • apple iphone os (iOS) versions prior to iOS 12.3 (fixed in iOS 12.3)
  • apple mac os x (macOS Mojave) versions prior to macOS Mojave 10.14.5 (fixed in 10.14.5)
  • apple tvos versions prior to tvOS 12.3 (fixed in tvOS 12.3)
  • +1 more
masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact…
Full article463 words · extracted from helpnetsecurity.com · click to collapse

Another month, another batch of Apple security updates that users of the firm’s computers, phones, tablets, streaming devices and smart watches will be prompted to implement.

Apple May 2019 security updates

Flaws fixed in most of the updates

As per usual, WebKit – the browser engine used in Apple’s Safari browser and other products – has the most number of flaws fixed.

Most of the WebKit flaws are memory corruption issues that can be triggered by processing maliciously crafted web content and could lead to arbitrary code execution. Those are fixed in macOS, iOS, tvOS, Safari and (in a more limited number) in the watchOS update.

When updated, all of those Apple devices will also receive fixes for three flaws in XNU, the OS kernel they have in common. One of these, CVE-2019-8605, could be exploited by a malicious application to execute arbitrary code with system privileges.

They also have in common fixes for four vulnerabilities affecting the SQLite component. All of them were flagged by Omer Gull of Checkpoint Research and one of them can be triggered by sending a maliciously crafted SQL query and could lead to arbitrary code execution.

Interesting fixes

Among the vulnerabilities fixed in macOS, there are some more unusual than others:

  • A flaw in DesktopSevices that could allow a malicious application to bypass Gatekeeper checks (CVE-2019-8589)
  • An EFI authentication issue that may result in users unexpectedly getting logged in to another user’s account (CVE-2019-8634).

Also of note are two flaws in the CoreAudio component that can be triggered by the OS processing a maliciously crafted audio or movie file (CVE-2019-8592, CVE-2019-8585).

One of these has also been fixed in the iOS update, along with:

  • CVE-2019-8626, a Mail flaw that could be triggered via a maliciously crafted message to lead to a DoS condition
  • CVE-2019-8617, a flaw in the Photo Storage component that could allow a sandboxed to circumvent sandbox restrictions
  • CVE-2019-8620, a Wi-Fi vulnerability that could be exploited by attackers to track devices by their WiFi MAC address.

The tvOS and watchOS updates have patches for, more or less, the same vulnerabilities.

Security update for Apple TV software

Finally, it’s interesting to note that for the first time in over three years Apple has delivered a security update for Apple TV Software, the tvOS precursor that powers third-generation Apple TVs.

The software is based on iOS and the fixes it received are for:

  • A Bluetooth input validation issue (CVE-2017-14315) that could be exploited remotely to cause an unexpected application termination or arbitrary code execution
  • Two flaws in the Wi-Fi component (CVE-2017-9417, CVE-2017-6975) that could only be exploited by attackers in range, but could result in arbitrary code execution on the Wi-Fi chip.

All the flaws date back to 2017. The Bluetooth one can be exploited in so-called BlueBorne attacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/05/14/apple-may-2019-security-updates-fix-numerous-issues/