ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23529
WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari

CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known.

Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched.

8.810% KEV
  • Apple iPhone OS (iOS) iOS versions prior to the fixed releases; fixed in iOS 16.3.1 and in iOS 15.7.4 on the legacy branch
  • Apple iPadOS iPadOS versions prior to the fixed releases; fixed in iPadOS 16.3.1 and in iPadOS 15.7.4 on the legacy branch
  • Apple macOS (Ventura) macOS Ventura versions prior to 13.2.1
  • +1 more
massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran…
CVE-2023-32439
Type Confusion in Apple WebKit (Safari, iOS, iPadOS, macOS) Enables Code Execution

Apple's WebKit engine, used by Safari and shipped with iOS, iPadOS, and macOS, contains a type confusion vulnerability (CWE-843) that leads to code execution when processing maliciously crafted web content. An attacker can trigger the flaw by inducing a victim to load attacker-controlled web content, for example by visiting a crafted webpage or opening malicious HTML in any application that renders it with WebKit. Successful exploitation grants the attacker arbitrary code execution within the web-content processing context of the affected browser or application. The exposure is broad: every iPhone, iPad, and Mac running vulnerable WebKit builds is affected, and the flaw could also impact HTML parsers in non-Apple products that rely on WebKit. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-23, confirming known in-the-wild exploitation (ransomware use unknown); no public proof-of-concept is known, and CISA's required action is to apply updates per vendor instructions.

Do: Apply Apple's security updates for iOS, iPadOS, macOS, and Safari immediately, following vendor instructions as required by the CISA KEV catalog, since the flaw is confirmed exploited in the wild. Administrators should also inventory any non-Apple applications, HTML parsers, or embedded browsers that use WebKit and apply the corresponding vendor patches when available. Until patching is complete, treat unsolicited web links and HTML content as a primary attack vector and prioritize updates on internet-facing and user-facing Apple systems.

8.8
group max
24% KEV
  • Apple Safari (WebKit)
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • +2 more
masshundreds of millions to over a billion users (WebKit ships with every iPhone, iPad, and Mac)
CVE-2023-28205
Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile).

Do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content.

8.827% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +3 more
mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari)
CVE-2023-28206
Out-of-Bounds Write in Apple IOSurfaceAccelerator Allows Kernel-Level Code Execution

Apple's IOSurfaceAccelerator component in iOS, iPadOS, and macOS contains an out-of-bounds write flaw (CWE-787). The bug is triggered by an application running locally on the device, which can corrupt memory in the component during a write past a buffer boundary. A successful exploit allows the app to execute arbitrary code with kernel privileges, giving it full control of the device beyond the normal app sandbox. Any user of an Apple iOS, iPadOS, or macOS device running an affected, unpatched version is exposed. The flaw was added to CISA KEV on 2023-04-10, confirming known in-the-wild exploitation; ransomware use is unknown, no public PoC is available, and EPSS assigns a 24.5% probability of exploitation within 30 days (98th percentile).

Do: Update all iPhones, iPads, and Macs to the latest iOS/iPadOS/macOS versions available as of April 2023, per CISA's required action and Apple's security advisories. Use MDM or patch-reporting tooling to inventory endpoints and confirm no devices remain on pre-patch builds. Because exploitation is confirmed in the wild and any local app can act as the trigger, patching is the primary mitigation and there is no dependable configuration workaround.

8.623% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's active iPhone/iPad/Mac installed base exceeds 1 billion)
CVE-2023-37450
+1 in the same advisory: …38606
Arbitrary Code Execution in Apple WebKit (iOS, iPadOS, macOS, Safari, tvOS, watchOS)

CVE-2023-37450 is a high-severity (CVSS 8.8) arbitrary code execution vulnerability in Apple's WebKit browser engine, affecting iOS, iPadOS, Safari, macOS Ventura, tvOS, watchOS, and WebKitGTK. It is triggered when an affected device processes maliciously crafted web content — for example, when a user is lured into visiting an attacker-controlled webpage (user interaction is required, hence the UI:R CVSS vector). Successful exploitation grants the attacker arbitrary code execution within the web-content/browser context, the typical entry point for full iPhone, iPad, or Mac compromise chains. Anyone running iPhone OS/iPadOS earlier than 16.6, Safari earlier than 16.5.2, macOS Ventura earlier than 13.5, tvOS earlier than 16.6, watchOS earlier than 9.6, or unpatched WebKitGTK builds is affected. Apple reports the issue may have been actively exploited before it was patched, CISA added it to the KEV catalog on 2023-07-13, and EPSS assigns an 18.9% probability (97th percentile) of exploitation over the next 30 days.

Do: Upgrade immediately to iOS 16.6 / iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6, and watchOS 9.6, or apply the latest available patch for older OS branches on devices that cannot take the 16.x/Ventura updates; this is a CISA KEV entry with a federal remediation requirement. Because exploitation occurs through normal web browsing, patching is the only reliable mitigation — avoid untrusted websites as an interim measure. WebKitGTK users should update to the latest patched WebKitGTK release and verify that dependent applications have been rebuilt against the fixed library.

8.8
group max
19% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 16.6
  • Apple iPadOS All versions prior to iPadOS 16.6
  • Apple Safari All versions prior to Safari 16.5.2
  • +4 more
mass≈2 billion active Apple devices (WebKit is the web engine for iOS/iPadOS, Safari, tvOS and watchOS); no public counts of exploited devices are known
CVE-2023-41061
Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS

Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11.

Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds.

7.84% KEV
  • Apple iPhone OS (iOS) all versions prior to 16.6.1
  • Apple iPadOS all versions prior to 16.6.1
  • Apple watchOS all versions prior to 9.6.2
massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched)
CVE-2023-41064
ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution

CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs.

Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices.

7.845% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion)
CVE-2023-41993
+2 in the same advisory: …41992 …41991
WebKit Code Execution Flaw in Apple iOS, iPadOS, macOS, and Safari

Apple's WebKit engine, which renders web content for Safari and for essentially all HTML processing on iOS, iPadOS, and macOS, contains a flaw that leads to code execution when processing maliciously crafted web content. It is triggered when a user's browser or embedded web view loads attacker-controlled web content, so simply visiting a hostile page can be enough. Successful exploitation could allow arbitrary code execution within the affected application's context, a common stepping stone to broader device compromise. All users of Apple iOS, iPadOS, macOS, and Safari are potentially affected, as are users of non-Apple products that rely on WebKit for HTML processing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known.

Do: Apply Apple's latest security updates for iOS, iPadOS, macOS, and Safari that patch WebKit, following the vendor instructions referenced by the CISA KEV entry, and treat unpatched WebKit builds as actively exploited. Until systems are patched, restrict exposure to untrusted web content (e.g., limit browsing and in-app web views to trusted sites for high-risk users). Also inventory any non-Apple applications or HTML-processing components in your environment that bundle WebKit and update them as their maintainers ship fixes.

8.8
group max
29% KEV
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • Apple macOS (WebKit)
  • +2 more
mass1+ billion devices/users (WebKit ships in Safari and all web-content rendering on iOS, iPadOS, and macOS)
CVE-2023-42917
+1 in the same advisory: …42916
WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution

CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).

Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.

8.8
group max
9% KEV
  • apple iphone os (iOS) versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1
  • apple ipados versions prior to iPadOS 17.1.2
  • apple macos (Sonoma) versions prior to macOS Sonoma 14.1.2
  • +4 more
masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base)
CVE-2023-5217
Heap Buffer Overflow in Google Chromium libvpx (CVE-2023-5217) Added to CISA KEV

CVE-2023-5217 is a heap buffer overflow (CWE-787) in the VP8 encoding path of libvpx, the open-source video codec library bundled with Google's Chromium/Chrome browser. A remote attacker can trigger the flaw by luring a user to a crafted HTML page whose web content invokes the vulnerable VP8 encoding code, corrupting the heap and potentially achieving code execution in the affected browser. Anyone running Google Chrome/Chromium — or other browsers and software that embed libvpx, as CISA notes the library's use is 'not limited to Google Chrome' — is affected. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-10-02 (ransomware association: unknown), though no public proof-of-concept is available and a CVSS score has not been published; EPSS puts the 30-day exploitation probability at 49% (99th percentile). Defenders should treat this as an actively exploited browser vulnerability requiring prompt patching.

Do: Update Chrome/Chromium to the vendor release that fixes CVE-2023-5217 — Google shipped the fix with its late-September 2023 stable-channel security update, so verify the exact build number in Google's advisory (it is not specified in the source data). Also patch any other products bundling libvpx (other browsers, media/ffmpeg-based tooling) per vendor instructions, and ensure KEV compliance by applying the required mitigations or discontinuing use of affected builds by the CISA deadline.

8.849% KEV PoC
  • Google Chromium libvpx (VP8 encoding component, as bundled in Chrome/Chromium)
  • Google Chrome (browser shipping Chromium libvpx)
masson the order of 1–3+ billion users/devices (Chrome's global installed base; roughly two-thirds desktop browser market share)
Full article355 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 30, 2023

Apple released emergency security updates to fix two actively exploited zero-day flaws impacting iPhone, iPad, and Mac devices.

Apple released emergency security updates to address two zero-day vulnerabilities impacting iPhone, iPad, and Mac devices. The flaws are actively exploited in attacks in the wild, both issues reside in the WebKit browser engine.

The first vulnerability, tracked as CVE-2023-42916, is an out-of-bounds read. An attacker can trick a victim into visiting specially crafted web content to disclose sensitive information.

“Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.” reads the advisory.

The company addressed the flaw with improved input validation.

The second vulnerability, tracked as CVE-2023-42917, is a memory corruption vulnerability. An attacker can trick a victim into visiting specially crafted web content to potentially execute arbitrary code on the impacted devices.

The company addressed the flaw with improved locking.

Clément Lecigne of Google’s Threat Analysis Group discovered both vulnerabilities. The fact that the issues were discovered by Google TAG suggests they were exploited by a nation-state actor or by a surveillance firm.

Apple addressed the flaws with the release of iOS 17.1.2, iPadOS 17.1.2macOS Sonoma 14.1.2, and Safari 17.1.2.

The vulnerabilities impact the following devices:

  • iPhone XS and later
  • iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
  • Macs running macOS Monterey, Ventura, Sonoma

The IT giant fixed 19 zero-day flaws from the start of the year.

The remaining seventeen vulnerabilities are

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/155026/security/apple-emergency-security-updates-2-zero-day.html