ZeroHour
The Recordpublished ()ingested 1

Apple refused to pay bug bounty to Russian cybersecurity firm Kaspersky Lab

criticalExploit / PoCimportance 60CVE-2023-38606

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-38606
Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS

CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected.

Do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines.

5.53% KEV
  • apple iPhone OS (iOS) iOS versions prior to iOS 15.7.8 and iOS 16 versions prior to iOS 16.6 (fixed in iOS 15.7.8 and iOS 16.6)
  • apple iPadOS iPadOS versions prior to 15.7.8 and iPadOS 16 versions prior to 16.6 (fixed in iPadOS 15.7.8 and iPadOS 16.6)
  • apple macOS Big Sur versions prior to 11.7.9 (fixed in macOS Big Sur 11.7.9)
  • +4 more
mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023)
Full article810 words · extracted from therecord.media · click to collapse

Apple declined to issue a bug bounty to the Russian cybersecurity company Kaspersky Lab after it disclosed four zero-day vulnerabilities in iPhone software that were allegedly used to spy on Kaspersky employees as well as Russian diplomats.

A spokesperson for Kaspersky Lab told Recorded Future News that the company’s research team considered their work “eligible for Bug Bounty rewards from Apple. However, when asked about it, we received a decline from the Apple Security team referring to the dedicated policy.”

Apple did not provide a comment when contacted by Recorded Future News.

Bug bounties are a common way for companies to encourage researchers to disclose vulnerabilities to them instead of monetizing them by selling them to malicious actors that might exploit them. 

Kaspersky publicly disclosed a suspected highly sophisticated spying campaign last year, with the company’s chief executive and namesake Eugene Kaspersky describing it as “an extremely complex, professionally targeted cyberattack” impacting “several dozen iPhones of the company’s employees — both top and middle-management.”

Operation Triangulation, as the spying campaign was named, was “definitely the most sophisticated attack chain we have ever seen,” the Kaspersky researchers said, with an explanation of it including 13 separate bullet points.

Due to the sophistication of how the vulnerabilities were exploited and the limited targeting of the attackers — seeking intelligence material rather than financial details — it was suspected to be state-sponsored.

On the same day as Kaspersky’s disclosure, Russia's Federal Security Service (FSB) accused the United States and Apple of having collaborated to enable the U.S. to spy on Russian diplomats.

The FSB provided few public details regarding the alleged operation affecting diplomats, but Russia’s computer security agency separately claimed that the indicators of compromise of both campaigns were the same.

The key problem potentially indicating collaboration was a vulnerability tracked as CVE-2023-38606. According to Kaspersky, this affected a particularly unusual hardware feature that was not actually used by any iOS firmware. As such the researchers suggested it may have been intended for debugging or testing purposes or was included in the iPhone operating system by mistake.

“We do not know how the attackers learned to use this unknown hardware feature or what its original purpose was. Neither do we know if it was developed by Apple or if it's a third-party component,” stated Kaspersky.

At the time a spokesperson for Apple disputed the allegations it had colluded with a state to enable any spying on its customers, stating: “We have never worked with any government to insert a backdoor into any Apple product and never will.”

Once bitten, twice shy 

The allegation that Apple refused to pay a bug bounty reward to Kaspersky comes amid an intensifying period of antagonism between the United States and the Russian Federation following Moscow’s full-blown invasion of Ukraine.

In a statement that March, Apple said: “We are deeply concerned about the Russian invasion of Ukraine and stand with all of the people who are suffering as a result of the violence”

The company, which is an American multinational, announced that as a result of the invasion it was suspending all of its product sales in Russia and removing state-controlled media organizations’ apps from its App Store, as well as limiting access to services such as Apple Pay for existing customers.

Although Kaspersky is not specifically sanctioned in the United States in relation to the Ukraine conflict, the Department of Homeland Security had previously banned its products from government use on security grounds due to the level of control anti-virus software requires on a computer and the risks attached to that control for a company based in Russia.

Kaspersky has also been accused of allowing the FSB to use its anti-virus software to scan computers for intelligence material, although no public evidence of this has been produced and Kaspersky has denied the claims, stating that if its team ever detects classified material then it is ordered to be immediately deleted.

Speaking to Russian-language media agency RTVI, Kaspersky’s research head Dmitry Galov said that typically cybersecurity companies like Kaspersky nominated a charity to receive the funds from the Apple Bug Bounty program instead of collecting the revenue itself. 

He added that although Kaspersky was confident the attacker was state-sponsored, he and his research team did not have the technical data needed to identify which state may have been behind the attack.

A spokesperson for Kaspersky did not respond to whether it had nominated a charity when initially contacting Apple, nor whether the company’s refusal to issue a bounty would affect its decision to disclose vulnerabilities discovered in the future.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/kaspersky-apple-bug-bounty-declined