ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google TAG shares details about exploit chains used to install commercial spyware

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30900
Kernel Out-of-Bounds Write in Apple iOS, iPadOS, and macOS (Actively Exploited)

CVE-2021-30900 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS, iPadOS, and macOS, addressed by Apple with improved bounds checking. It is triggered locally when a user runs a malicious application crafted to exploit the flaw (CVSS local vector with user interaction required). Successful exploitation allows the attacker to execute arbitrary code with kernel privileges, effectively yielding full control of the device. Anyone running an affected build is exposed: iOS/iPadOS versions prior to 14.8.1 and 15.1, plus macOS builds listed in Apple's advisory. The bug has been exploited in the wild in commercial spyware campaigns observed by Google TAG in Italy, Malaysia, Kazakhstan, and the UAE, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30 (EPSS 5.2%, 92nd percentile; ransomware use unknown).

Do: Update devices to iOS/iPadOS 14.8.1 or 15.1 (or later) and apply the corresponding macOS security update per Apple's instructions, consistent with CISA's KEV required action. Inventory mobile fleets via MDM for devices still on older builds and prioritize remediation where spyware campaigns in Italy, Malaysia, Kazakhstan, or the UAE are relevant, checking device logs for signs of compromise since these exploit chains often bundle additional flaws.

7.85% KEV
  • Apple iPhone OS (iOS) iOS versions prior to 14.8.1 (14.x line) and prior to 15.1 (15.x line); fixed in iOS 14.8.1 and iOS 15.1
  • Apple iPadOS iPadOS versions prior to 14.8.1 (14.x line) and prior to 15.1 (15.x line); fixed in iPadOS 14.8.1 and iPadOS 15.1
  • Apple macOS
mass≈1B+ Apple devices (active iPhone/iPad/Mac installed base)
CVE-2022-1134
Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Type confusion in V8 in Google Chrome prior to 100.0.4896.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

NVD description · AI analysis pending
8.82% PoC
  • google chrome
CVE-2022-22706
Unprivileged Memory-Write Flaw in Arm Mali GPU Kernel Drivers

CVE-2022-22706 is a memory-safety flaw (CWE-119) in the Arm Mali GPU kernel driver that lets a local, non-privileged user gain write access to memory pages that should be read-only, potentially enabling privilege escalation or tampering with protected memory (CVSS 3.1: 7.8, local attack vector). It is triggered by a low-privileged local user interacting with the GPU driver on devices running affected Midgard (r26p0-r31p0), Bifrost (r0p0-r35p0), or Valhall (r19p0-r35p0) driver releases, which are widely shipped in Android SoCs such as those from MediaTek and HiSilicon. A successful attacker gains high confidentiality, integrity, and availability impact on the local device. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2023-03-30, and security reporting ties Mali GPU driver zero-day exploitation to commercial spyware campaigns targeting Android and iOS users in Italy, Malaysia, Kazakhstan, and the UAE. The fix reached end users through vendor firmware, including the June 2023 Android security update.

Do: Apply updated Arm Mali GPU kernel drivers via your device/SoC vendor's firmware, ensuring Android endpoints are on security patch levels that include the fix (the June 2023 Android Security Bulletin shipped the Mali driver fix). Enterprises should inventory Android devices using Mali-based SoCs (e.g., MediaTek, HiSilicon) and prioritize patching devices exposed to spyware-targeted users; no workarounds are documented, and the CISA KEV required action is to apply updates per vendor instructions.

7.81% KEV
  • Arm Midgard GPU kernel driver r26p0 through r31p0
  • Arm Bifrost GPU kernel driver r0p0 through r35p0
  • Arm Valhall GPU kernel driver r19p0 through r35p0
masshundreds of millions of Android devices (Mali GPUs are integrated into a large share of Android SoCs; subset running affected driver versions)
CVE-2022-3038
Use-After-Free in Chromium Network Service Affects Chrome, Edge, Opera

Google Chromium's Network Service contains a use-after-free vulnerability (CWE-416) that a remote attacker can trigger via a crafted HTML page, potentially causing heap corruption in the browser process. An attacker who successfully exploits the flaw could achieve memory corruption that may lead to browser crashes or arbitrary code execution when a user visits attacker-controlled web content. Any application built on Chromium is potentially affected, including but not limited to Google Chrome, Microsoft Edge, and Opera, meaning the impact spans a very large share of the world's browser users. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2023-03-30, indicating confirmed exploitation in the wild, though ransomware association is unknown and no public proof-of-concept is cataloged. No CVSS score is available yet, but EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile), underscoring elevated exploitation risk.

Do: Apply browser updates per vendor instructions immediately — update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers deployed in your environment to the latest vendor-supplied patched releases (exact fixed version numbers were not provided in this data; check each vendor's security advisory). Because the flaw is confirmed exploited in the wild and listed in CISA KEV, prioritize patching internet-facing browsing endpoints and users who routinely visit untrusted web content; there are no reliable workarounds beyond patching, though limiting browsing to trusted sites reduces exposure.

8.825% KEV PoC
  • Google Chromium Network Service
mass≈3+ billion browser users across Chromium-based browsers (Chrome, Edge, Opera and derivatives)
CVE-2022-3723
Actively Exploited V8 Type Confusion in Google Chrome (CVE-2022-3723)

CVE-2022-3723 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome, rated High severity with a CVSS 3.1 score of 8.8. It is triggered remotely when a user renders a crafted HTML page, allowing a remote attacker to potentially exploit heap corruption in the browser; the high confidentiality, integrity, and availability impact reflects likely code execution. All Google Chrome releases prior to 107.0.5304.87 are affected, and per CISA the underlying flaw resides in Google Chromium V8, so Chromium-based browsers embedding the same engine are similarly exposed pending their own updates. The flaw was exploited as a zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-28, and news coverage describes it as Google's ninth actively exploited Chrome zero-day of 2022, amid reports of spyware vendors exploiting zero-days in the wild. EPSS assigns a 7.9% probability (94th percentile) of exploitation activity in the next 30 days.

Do: Update Google Chrome to 107.0.5304.87 or later on all endpoints and restart the browser to complete the patch, verifying the installed version via chrome://version; apply the corresponding V8/Chromium update in any Chromium-based browsers your organization ships. CISA's KEV required action is to apply updates per vendor instructions, so prioritize managed fleets, user workstations, and any browsers exposed to untrusted web content. No public PoC or workaround is known, so patching is the sole effective mitigation.

8.88% KEV
  • Google Chrome all versions prior to 107.0.5304.87 (flaw is in the V8 engine, identified by CISA as Google Chromium V8)
mass≈3 billion users (Chrome's global install base across desktop and mobile)
CVE-2022-38181
Use-After-Free Vulnerability in Arm Mali GPU Kernel Driver (Bifrost/Valhall/Midgard)

CVE-2022-38181 is a use-after-free (CWE-416) in the Arm Mali GPU kernel driver in which GPU memory operations are mishandled, allowing unprivileged users to access freed memory. A low-privileged attacker can trigger the flaw and gain confidentiality, integrity, and availability impact (CVSS 3.1: 8.8 High), typically leveraged within exploit chains to escalate privileges in the kernel. The bug affects the Bifrost, Valhall, and Midgard Mali driver families across the version ranges listed below, meaning virtually any device running an affected Mali GPU driver is exposed, including Android smartphones such as Google Pixel devices. The vulnerability is being actively exploited: it was used in commercial spyware campaigns on Android and iOS devices reported in Italy, Malaysia, Kazakhstan, and the UAE, documented by Google TAG and GitHub Security Lab, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30.

Do: Apply updates per vendor instructions as required by CISA KEV: device makers and SoC integrators should upgrade the Mali GPU kernel driver to releases newer than the affected ranges (beyond r39p0 for Bifrost/Valhall and beyond r32p0 for Midgard). End users and administrators should promptly install the latest Android/security firmware updates from their device vendor and inventory devices running affected Mali drivers for prioritized patching.

8.814% KEV PoC ×2
  • Arm Bifrost GPU kernel driver r0p0 through r38p1, and r39p0
  • Arm Valhall GPU kernel driver r19p0 through r38p1, and r39p0
  • Arm Midgard GPU kernel driver r4p0 through r32p0
masshundreds of millions to billions of devices (Mali GPUs ship in a large share of Android smartphones and embedded Arm systems)
CVE-2022-4135
Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera)

CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists.

9.632% KEV PoC
  • Google Chromium GPU (GPU process component of the Chromium engine)
  • Google Chrome (Chromium-based browser)
  • Microsoft Edge (Chromium-based browser)
  • +1 more
mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown)
CVE-2022-4262
Type Confusion in Google Chrome V8 JavaScript Engine Exploited in the Wild (CVE-2022-4262)

CVE-2022-4262 is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome, in which incorrect handling of object types can lead to heap corruption. An attacker can trigger the flaw by convincing a user to visit a specially crafted HTML page, with no privileges or special network access required. Successful exploitation could allow remote code execution or information disclosure within the browser process, and the High severity rating and web-reachable attack vector reflect significant potential impact. All Google Chrome users running versions prior to 108.0.5359.94 are affected, as are users of Chromium-based browsers incorporating the vulnerable V8 code. The vulnerability was a zero-day exploited in the wild prior to the patch — attributed by media reports to commercial spyware vendors targeting Android and iOS devices — and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-12-05.

Do: Update Google Chrome to 108.0.5359.94 or later on all endpoints, and apply equivalent updates from vendors of Chromium-based browsers (e.g., Microsoft Edge, Brave, Opera) as they ship patched V8 builds. Verify the fixed version is running via chrome://settings/help or your patch-management inventory, and treat browser exploit chains as a spyware risk: review endpoint telemetry for signs of compromise, especially on mobile or high-target devices. CISA's required action is to apply updates per vendor instructions.

8.816% KEV
  • Google Chrome All versions prior to 108.0.5359.94
  • Google Chromium V8 V8 as shipped in Google Chrome prior to 108.0.5359.94
massWell over 1 billion users (Chrome has roughly 60%+ desktop browser market share and billions of active installs; unknown how many remain on pre-108.0.5359.94…
CVE-2022-42856
Type Confusion in Apple WebKit (Safari/iOS/macOS/tvOS), Actively Exploited

CVE-2022-42856 is a type confusion vulnerability (CWE-843) in Apple's WebKit web engine, addressed with improved state handling and affecting Safari, iPhone OS (iOS), iPadOS, macOS (Ventura) and tvOS. It is triggered when a user processes maliciously crafted web content, for example by visiting an attacker-controlled web page, in a WebKit-based browser or app. Successful exploitation may lead to arbitrary code execution on the affected device. Anyone running the affected Apple platforms below the December 2022 patch level (Safari 16.2, macOS Ventura 13.1, tvOS 16.2, iOS/iPadOS 15.7.2, iOS 16.1.2) was exposed, which effectively means most Apple users at the time of disclosure. Exploitation is confirmed: Apple reported the issue may have been actively exploited against iOS versions released before iOS 15.1, it was added to CISA KEV on 2022-12-14 (EPSS 8.5%, 95th percentile), and related reporting ties it to commercial spyware campaigns in Italy, Malaysia, Kazakhstan and the UAE.

Do: Update immediately to Safari 16.2, macOS Ventura 13.1, tvOS 16.2, and iOS/iPadOS 15.7.2 (for iOS 15-era devices) or iOS 16.1.2 (for iOS 16-era devices), or any later release; this is a CISA KEV entry whose required action is to apply vendor updates. Because the flaw was exploited as a zero-day against iOS versions before iOS 15.1 and is linked to commercial spyware campaigns, treat patching as urgent and verify that all managed and BYOD iPhones and iPads are on a fixed version; on iOS, all third-party browsers and most web-content apps use WebKit, so the OS update itself is the remediation rather than switching browsers.

8.89% KEV
  • Apple Safari All versions prior to 16.2 (macOS)
  • Apple iPhone OS (iOS) iOS 15 versions prior to 15.7.2 and iOS 16 versions prior to 16.1.2 (actively exploited against iOS releases before iOS 15.1)
  • Apple iPadOS All versions prior to 15.7.2
  • +2 more
mass~1 billion+ Apple devices at disclosure (every iOS/iPadOS/macOS/tvOS device below the December 2022 patch level; Apple's active installed base exceeds 1…
CVE-2023-0266
Use-After-Free in Linux Kernel ALSA PCM Enables Local Privilege Escalation

CVE-2023-0266 is a use-after-free (CWE-416) in the ALSA PCM subsystem of the Linux kernel: the SNDRV_CTL_IOCTL_ELEM_READ32 and SNDRV_CTL_IOCTL_ELEM_WRITE32 compat ioctl handlers are missing locking, so a local user can trigger access to a control element that has already been freed. An attacker with low-privilege local user access on a system with the ALSA subsystem can exploit this race to escalate privileges and gain ring0 (kernel-level) access. The flaw affects Linux kernel builds fixed by commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e, including kernels shipped in distributions such as Debian. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30, and reporting around commercial surveillance spyware campaigns (per Google TAG) indicates it was used as a zero-day in spyware exploit chains. EPSS assigns a 3.7% probability of exploitation in the next 30 days (89th percentile), and no public proof-of-concept is known.

Do: Upgrade affected systems to a Linux kernel that includes fix commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e, and apply vendor updates per instructions — for Debian systems, install the updated kernel packages from Debian security updates and reboot to load the patched kernel. Prioritize multi-user servers and workstations where untrusted or low-privilege local users can execute code, as this is a local privilege escalation vector with in-the-wild spyware exploitation. As interim mitigation, restrict which local users can access ALS device nodes (e.g., /dev/snd/*) or limit local account access on exposed systems.

7.04% KEV
  • Linux Kernel Kernel builds containing the vulnerable ALSA PCM code prior to fix commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e (upgrade past this commit); no specific versi
  • Debian Linux
masshundreds of millions of Linux installations broadly (kernel runs on most servers, cloud instances, and Linux desktops); practically, multi-user systems with…
Full article756 words · extracted from securityaffairs.com · click to collapse

Google’s Threat Analysis Group (TAG) discovered several exploit chains targeting Android, iOS, and Chrome to install commercial spyware.

Google’s Threat Analysis Group (TAG) shared details about two distinct campaigns which used several zero-day exploits against Android, iOS and Chrome. The experts pointed out that both campaigns were limited and highly targeted. The threat actors behind the attacks used both zero-day and n-day exploits in their exploits.

The exploit chains were used to install commercial spyware and malicious apps on targets’ devices.

The first campaign was spotted in November 2022, the exploit chains discovered by TAG researchers were affecting Android and iOS and were delivered via bit.ly links sent over SMS to users. The campaign aimed at users in Italy, Malaysia, and Kazakhstan. Once clicked the links, targets are initially redirected to pages hosting exploits for either Android or iOS, then redirected to legitimate websites (e.g. Italian-based shipment and logistics company BRT, or a popular Malaysian news website).

The initial landing page was observed hosting the exploits for a WebKit remote code execution zero-day (CVE-2022-42856) and a sandbox escape (CVE-2021-30900) issue.

In this campaign, the final payload was a simple stager that pings back the GPS location of the device and allows to install an .IPA file (iOS application archive) onto the affected device.

The Android exploit chain in the first campaign targeted users on phones with an ARM GPU running Chrome versions prior to 106. The exploit chain consisted of three exploits, including one 0-day:

  • CVE-2022-3723, a type confusion vulnerability in Chrome, found by Avast in the wild and fixed in October 2022 in version 107.0.5304.87.
  • CVE-2022-4135, a Chrome GPU sandbox bypass only affecting Android (0-day at time of exploitation), fixed in November 2022. Sergei Glazunov from Project Zero helped analyze the exploit and wrote a root cause analysis for this bug.
  • CVE-2022-38181, a privilege escalation bug fixed by ARM in August 2022. It is unclear if attackers had an exploit for this vulnerability before it was reported to ARM.

“We were unable to obtain the final payload for this exploit chain.” reads the post published Google TAG. “When ARM released a fix for CVE-2022-38181, patches were not immediately incorporated by vendors, resulting in the bugs exploitation. This was recently highlighted by blog posts from Project Zero and Github Security Lab.”

The second campaign was spotted in December 2022 when the researchers discovered an exploit chain targeting the latest version of the Samsung Internet Browser using multiple zero-days and n-days.

The victims of the attack were people in the United Arab Emirates (UAE) that were targeted by Variston commercial spyware. The attackers used one-time links sent via SMS to targets’ devices.

The link directed users to a landing page that is the same TAG examined in the Heliconia framework developed by Variston. The exploit chain delivered a fully featured Android spyware suite written in C++ that was able to steal data from various chat and browser applications. Experts believe that the threat actor could be a customer or partner of Variston, or a third-party working closely with the spyware vendor.

The exploit chain included the following 0-days and n-days:

  • CVE-2022-4262, a type confusion vulnerability in Chrome fixed in December 2022 (0-day at time of exploitation) – similar to CVE-2022-1134.
  • CVE-2022-3038, a sandbox escape in Chrome fixed in August 2022, in version 105 and found by Sergei Glazunov in June 2022.
  • CVE-2022-22706, a vulnerability in Mali GPU Kernel Driver fixed by ARM in January 2022 and marked as being used in the wild. At the time of delivery, the latest Samsung firmware had not included a fix for this vulnerability. This vulnerability grants the attacker system access.
  • CVE-2023-0266, a race condition vulnerability in the Linux kernel sound subsystem reachable from the system user and that gives the attacker kernel read and write access (0-day at time of exploitation).

Google TAG shared indicators of compromise (IoCs) for both campaigns.

“These campaigns are a reminder that the commercial spyware industry continues to thrive. Even smaller surveillance vendors have access to 0-days, and vendors stockpiling and using 0-day vulnerabilities in secret pose a severe risk to the Internet.” concludes the report. “These campaigns may also indicate that exploits and techniques are being shared between surveillance vendors, enabling the proliferation of dangerous hacking tools. We remain committed to updating the community, and taking steps to protect users, as we uncover these campaigns.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, exploit chains)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144174/hacking/exploit-chains-zero-day-spyware.html