ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes FaceTime eavesdropping bug, two iOS zero-days

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-6223
Apple iOS/macOS Group FaceTime Auto-Answer Flaw Enables Silent Eavesdropping

A logic flaw in the handling of Group FaceTime calls on Apple iOS and macOS let the initiator of a Group FaceTime call cause the recipient's device to answer automatically, without the user accepting. An attacker who called a victim's FaceTime identity could thereby listen in on the recipient's surroundings before the call was accepted - a silent eavesdropping condition consistent with the CVSS confidentiality-high rating. Users of iPhones and iPads running iOS releases with Group FaceTime prior to 12.1.4, and Macs running macOS Mojave prior to the 10.14.3 Supplemental Update, were affected. Apple shipped fixes in iOS 12.1.4 and the macOS Mojave 10.14.3 Supplemental Update. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation, while EPSS puts near-term exploitation probability at about 2.6% (85th percentile) and no public proof-of-concept code is known.

Do: Upgrade iPhones and iPads to iOS 12.1.4 or later and Macs to macOS Mojave 10.14.3 Supplemental Update or later. As an interim mitigation, disable FaceTime or avoid placing/accepting Group FaceTime calls until patched, and verify managed fleets have the updates applied per the CISA KEV required action.

7.53% KEV
  • apple iphone os (iOS on iPhone/iPad) iOS releases with Group FaceTime prior to 12.1.4 (fixed in iOS 12.1.4)
  • apple mac os x (macOS Mojave) macOS Mojave prior to 10.14.3 Supplemental Update (fixed in 10.14.3 Supplemental Update)
masshundreds of millions of consumer devices (Apple's active iPhone/Mac install base, with the affected Group FaceTime-era iOS and macOS Mojave releases widely…
CVE-2019-7286
Out-of-Bounds Write Local Privilege Escalation in Apple iOS and macOS

CVE-2019-7286 is a memory corruption flaw (an out-of-bounds write, CWE-787) in Apple's iOS and macOS that Apple addressed with improved input validation. It is triggered locally: the CVSS vector shows a local attack vector requiring user interaction, and an application that corrupts memory through the flaw may gain elevated privileges with high impact on confidentiality, integrity, and availability. Users running iPhones or iPads on iOS before 12.1.4, or macOS Mojave systems without the 10.14.3 Supplemental Update, are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), which indicates confirmed exploitation in the wild, and EPSS assigns it a 15.6% probability of exploitation within 30 days (97th percentile). No public proof-of-concept is catalogued, but defenders should treat it as actively exploited.

Do: Update all iPhones and iPads to iOS 12.1.4 or later and apply the macOS Mojave 10.14.3 Supplemental Update (or a later macOS release) on Macs, per the CISA KEV required action. Inventory for devices that cannot run the fixed versions, restrict untrusted applications on them or retire them, since the flaw allows local apps to gain elevated privileges. Given the KEV listing, treat this as an actively exploited vulnerability and prioritize patching in any KEV-driven remediation program.

7.816% KEV
  • Apple iPhone OS (iOS) All versions prior to iOS 12.1.4
  • Apple macOS (Mac OS X) - Mojave macOS Mojave prior to the 10.14.3 Supplemental Update
masshundreds of millions of Apple devices affected at the time of disclosure; current count of unpatched legacy devices unknown
CVE-2019-7287
Out-of-Bounds Write in Apple iOS Allows Kernel-Privilege Code Execution

Apple iOS versions prior to 12.1.4 contain a memory corruption flaw — an out-of-bounds write (CWE-787) — which Apple fixed with improved input validation in iOS 12.1.4. Based on the flaw's CVSS scoring (local attack vector, user interaction required), it is triggered when a user opens or runs a malicious application on the device. A successful exploit lets that application execute arbitrary code with kernel privileges, giving the attacker full device control and access to all data on the phone. All Apple iPhones (iPhone OS) running iOS versions before 12.1.4 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), confirming known in-the-wild exploitation; EPSS currently assigns a 4.6% probability of exploitation activity within 30 days (91st percentile), no public proof-of-concept is cataloged, and ransomware use is unknown.

Do: Apply Apple's update without delay, per CISA KEV's required action: update all iPhones and iOS devices to iOS 12.1.4 or later. Inventory your fleet for devices still running iOS 12.1.3 or earlier and prioritize patching them; on unpatched legacy devices, avoid opening untrusted applications until updated. Where hardware allows, move older devices off iOS 12 to a currently supported iOS release.

7.85% KEV
  • Apple iPhone OS (iOS) iOS versions prior to 12.1.4 (i.e., 12.1.3 and earlier at time of disclosure; fixed in iOS 12.1.4)
mass≈hundreds of millions of iPhone devices at time of disclosure (early 2019)
CVE-2019-7288
The issue was addressed with improved validation on the FaceTime server.

The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos .

NVD description · AI analysis pending
9.81%
  • apple iphone os
  • apple mac os x
CVE-2019-7290
+1 in the same advisory: …7289
An access issue was addressed with additional sandbox restrictions.

An access issue was addressed with additional sandbox restrictions. This issue is fixed in Shortcuts 2.1.3 for iOS. A sandboxed process may be able to circumvent sandbox restrictions.

NVD description · AI analysis pending
10.0
group max
1%
  • apple shortcuts
Full article303 words · extracted from helpnetsecurity.com · click to collapse

Apple has pushed out critical security updates for iOS and macOS, which fix the “Facepalm” FaceTime eavesdropping bug but also two zero-day flaws that, according to Google researchers, have been exploited in the wild.

FaceTime eavesdropping bug

Fixed vulnerabilities

The Facepalm bug (CVE-2019-6223) affects FaceTime Groups both on iOS and macOS, and was discovered by Grant Thompson, a high schooler from Arizona.

After the existence of the flaw and demontration videos of its exploitation were made public, Apple decided to temporarily disable the FaceTime service until they can come up with a fix.

The flagging of this flaw also prompted Apple to do a thorough security audit of the FaceTime service, which lead to the discovery of a bug affecting with Live Photos (CVE-2019-7288).

We don’t know much about the two zero-days flagged by Google researchers, except that:

  • CVE-2019-7286 affects the Foundation framework and is a memory corruption issue that could be exploited by an app to gain elevated privileges
  • CVE-2019-7287 affects the IOKit framework and is a memory corruption flaw that could be exploited by an app to execute arbitrary code with kernel privileges.

Google and Apple are keeping mum on how these issues are being exploited.

Users are advised to update their iOS and macOS devices as soon as possible. Those who have disabled FaceTime on their devices when the Facepalm flaw was first publicized should remember to enable the service again.

Finally, those using the Shortcuts app for iOS should also update it to the newest version available (2.1.3).

The update fixes CVE-2019-7289, a parsing issue that could allow a local user to view sensitive user information, and CVE-2019-7290, an access issue that could allow a sandboxed process to circumvent sandbox restrictions.

The latter flaw can be exploited by attackers via malicious shortcuts, allowing them to steal targets’ sensitive and personal information.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/02/08/facetime-eavesdropping-bug/