Apple rushes fixes for exploited zero-days in iPhones and Macs (CVE-2023-28205, CVE-2023-28206)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28205 | Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile). Do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content. | 8.8 | 27% | KEV |
| mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari) | |
| CVE-2023-28206 | Out-of-Bounds Write in Apple IOSurfaceAccelerator Allows Kernel-Level Code Execution Apple's IOSurfaceAccelerator component in iOS, iPadOS, and macOS contains an out-of-bounds write flaw (CWE-787). The bug is triggered by an application running locally on the device, which can corrupt memory in the component during a write past a buffer boundary. A successful exploit allows the app to execute arbitrary code with kernel privileges, giving it full control of the device beyond the normal app sandbox. Any user of an Apple iOS, iPadOS, or macOS device running an affected, unpatched version is exposed. The flaw was added to CISA KEV on 2023-04-10, confirming known in-the-wild exploitation; ransomware use is unknown, no public PoC is available, and EPSS assigns a 24.5% probability of exploitation within 30 days (98th percentile). Do: Update all iPhones, iPads, and Macs to the latest iOS/iPadOS/macOS versions available as of April 2023, per CISA's required action and Apple's security advisories. Use MDM or patch-reporting tooling to inventory endpoints and confirm no devices remain on pre-patch builds. Because exploitation is confirmed in the wild and any local app can act as the trigger, patching is the primary mitigation and there is no dependable configuration workaround. | 8.6 | 23% | KEV |
| masshundreds of millions of devices (Apple's active iPhone/iPad/Mac installed base exceeds 1 billion) |
Full article460 words · extracted from helpnetsecurity.com · click to collapse
Apple has pushed out security updates that fix two actively exploited zero-day vulnerabilities (CVE-2023-28205, CVE-2023-28206) in macOS, iOS and iPadOS.

Reported by researchers Clément Lecigne of Google’s Threat Analysis Group (TAG) and Donncha Ó Cearbhaill, the head of Amnesty International’s Security Lab, the vulnerabilities have been exploited in tandem to achieve full device compromise – with the likely (though not confirmed) goal to install spyware on target devices.
About the vulnerabilities
CVE-2023-28205 is a use after free issue in the WebKit browser engine, which is used by Safari and all web browsers on iOS and iPadOS. The flaw can be triggered via maliciously crafted web content and may lead to arbitrary code execution.
CVE-2023-28206 is an out-of-bounds write issue in IOSurfaceAccelerator that can be exploited by a malicious app to execute arbitrary code with kernel privileges.
The former can be used to perform a drive-by, zero-click attack resulting in the silent installation of malware on the target device. The latter allows attackers to escape Safari’s sandbox (i.e., escalate privileges) and achieve full system access.
“Ironically, kernel-level bugs that rely on a booby-trapped app are often not much use on their own against iPhone or iPad users, because Apple’s strict App Store ‘walled garden’ rules make it hard for attackers to trick you installing a rogue app in the first place,” says Paul Ducklin, Sophos Head of Technology for the Asia Pacific region.
“But when attackers can combine a remote browser-busting bug with a local kernel-busting hole, they can sidestep the App Store problem entirely.”
Security updates for Macs, iPhones and iPads are available
Since Friday (April 7), Apple has released security updates for newer macOS (13.3.1), iOS and iPad OS (16.4.1) versions, and then quickly backported the patches to fix the flaws in older (macOS 12.6.5 and 11.7.6, and iOS/iPad 15.7.5) versions.
Users of macOS Monterey and Big Sur must implement the offered OS update AND the Safari update to squash both bugs.
German security researcher and hacker of Apple devices Linus Henze has already published a PoC for CVE-2023-28206 that triggers the flaw and should lead to an exploitable kernel panic.
Unfortunately, there are no details available about the attacks performed by exploiting CVE-2023-28205 and CVE-2023-28206. As noted before, the fact that Amnesty International’s Security Lab was involved in the discovery points to the vulnerabilities being exploited in limited attacks to install spyware on devices belonging to human rights advocates. Nevertheless, all Mac, iPhone and iPad users are advised to upgrade their OSes as soon as possible.
The Cybersecurity and Infrastructure Security Agency has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, and demands that US federal civilian executive branch agencies apply Apple’s updates by May 1, 2023.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/04/11/cve-2023-28205-cve-2023-28206/