ZeroHour
Ars Technica · Securitypublished ()ingested

Google researchers report critical 0

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-42916CVE-2023-42917

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-42917
+1 in the same advisory: …42916
WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution

CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).

Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.

8.8
group max
9% KEV
  • apple iphone os (iOS) versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1
  • apple ipados versions prior to iPadOS 17.1.2
  • apple macos (Sonoma) versions prior to macOS Sonoma 14.1.2
  • +4 more
masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base)
Full article213 words · extracted from arstechnica.com · click to collapse

Researchers in Google’s Threat Analysis Group have been as busy as ever with discoveries that have led to the disclosure of three high-severity zero-day vulnerabilities under active exploitation in Apple OSes and the Chrome browser in the span of 48 hours.

Apple on Thursday said it was releasing security updates fixing two vulnerabilities present in iOS, macOS, and iPadOS. Both of them reside in WebKit, the engine that drives Safari and a wide range of other apps, including Apple Mail, the App Store, and all browsers running on iPhones and iPads. While the update applies to all supported versions of Apple OSes, Thursday’s disclosure suggested that the in-the-wild attacks that are exploiting the vulnerabilities targeted earlier versions of iOS.

“Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1,” Apple officials wrote of both vulnerabilities, which are tracked as CVE-2023-42916 and CVE-2023-42917.

CVE-2023-42916 is an out-of-bounds read that allows hackers to obtain sensitive information when WebKit-powered apps process specially crafted online content. CVE-2023-42917 is a memory-corruption flaw that causes vulnerable devices to execute malicious code when processing hacker-created content for a WebKit app. Apple credited TAG’s Clément Lecigne with discovery of both vulnerabilities. Neither Apple nor Google provided details about the zero-day attacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/11/google-researchers-report-critical-zero-days-in-chrome-and-all-apple-oses/