CISA Warns of Active Exploitation Apple iOS and macOS Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-32844 | A race condition was addressed with improved state handling. A race condition was addressed with improved state handling. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6. An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication. NVD description · AI analysis pending | 6.3 | <1% |
| — | ||
| CVE-2022-48618 | Pointer Authentication Bypass in Apple iOS, iPadOS, macOS, tvOS and watchOS CVE-2022-48618 is a time-of-check/time-of-use (TOCTOU, CWE-367) memory-corruption flaw in Apple's operating systems that an attacker with arbitrary read and write capability can use to bypass Pointer Authentication (PAC), Apple's hardware-based mitigation that cryptographically signs pointers to defeat common exploit techniques. It is a local, low-privilege, high-complexity flaw (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N), so it is typically chained after another vulnerability that first grants an arbitrary memory read/write primitive rather than exploited on its own. By defeating PAC, the attacker removes a key defense that normally limits the reliability of memory-corruption exploits, making it easier to turn arbitrary memory access into full code execution on the device. Affected users are those running iOS/iPadOS prior to 16.2, macOS Ventura prior to 13.1, watchOS prior to 9.2, or tvOS prior to 16.2. Apple reported the flaw was already exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-31, confirming in-the-wild exploitation; no public proof-of-concept is known. Do: Upgrade to iOS/iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2 and tvOS 16.2 or later, prioritizing iPhones and iPads still running iOS below 15.7.1, which Apple confirmed were exploited. Inventory Apple endpoints via MDM/UEM and treat the KEV listing as a patching deadline per CISA's required action. Note that this flaw is typically chained after another bug granting arbitrary read/write, so ensure the full Apple security-update backlog is applied rather than treating PAC bypass in isolation. | 7.0 | <1% | KEV |
| mass>1 billion devices (combined Apple iPhone/iPad/Mac/Apple Watch/Apple TV install base, minus already-updated devices) | |
| CVE-2024-23222 | Apple WebKit Type Confusion Enables Arbitrary Code Execution Across iOS, macOS, tvOS CVE-2024-23222 is a type confusion flaw (CWE-843) in Apple's WebKit engine that allows arbitrary code execution when a device processes maliciously crafted web content, for example when a user is lured into loading attacker-controlled web pages in Safari or another WebKit-based view (the CVSS vector confirms user interaction is required). It affects a broad slice of the Apple ecosystem: Safari, iPhone OS/iPadOS on the iOS 15, 16 and 17 branches, macOS Monterey/Ventura/Sonoma, tvOS and visionOS, prior to the January 22, 2024 fixes. A successful attacker gains code execution on the target device with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). The flaw was fixed in Safari 17.3, iOS/iPadOS 17.3, and backported to iOS/iPadOS 15.8.7 and 16.7.5 for devices that cannot upgrade to iOS 17, plus macOS Monterey 12.7.3, Ventura 13.6.4, Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2024-01-23, one day after the fixes shipped, and is associated with the Coruna exploit kit, which reportedly chains multiple exploits to target iOS devices including older versions. Do: Update all affected devices to Safari 17.3, iOS/iPadOS 17.3 (or the iOS/iPadOS 15.8.7 and 16.7.5 backports for devices that cannot run 17), macOS Monterey 12.7.3, macOS Ventura 13.6.4, macOS Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Prioritize endpoints used for web browsing and mobile users, since exploitation only requires a user to process crafted web content. The CISA KEV listing (added 2024-01-23) makes applying these vendor updates mandatory under the KEV required action, so verify fleet versions and confirm no devices remain on pre-patch builds. | 8.8 | 11% | KEV |
| massover 1 billion active Apple devices (effectively Apple's entire unpatched iPhone/iPad/Mac/Apple TV fleet) |
Full article326 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 01, 2024Vulnerability / Software Update
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting iOS, iPadOS, macOS, tvOS, and watchOS to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability, tracked as CVE-2022-48618 (CVSS score: 7.8), concerns a bug in the kernel component.
"An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication," Apple said in an advisory, adding the issue "may have been exploited against versions of iOS released before iOS 15.7.1."
The iPhone maker said the problem was addressed with improved checks. It's currently not known how the vulnerability is being weaponized in real-world attacks.
Interestingly, patches for the flaw were released on December 13, 2022, with the release of iOS 16.2, iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, and watchOS 9.2, although it was only publicly disclosed more than a year later on January 9, 2024.
It's worth noting that Apple did resolve a similar flaw in the kernel (CVE-2022-32844, CVSS score: 6.3) in iOS 15.6 and iPadOS 15.6, which was shipped on July 20, 2022. It's not immediately clear if the two vulnerabilities are related.
"An app with arbitrary kernel read and write capability may be able to bypass Pointer Authentication," the company said at the time. "A logic issue was addressed with improved state management."
In light of the active exploitation of CVE-2022-48618, CISA is recommending that Federal Civilian Executive Branch (FCEB) agencies apply the fixes by February 21, 2024.
The development also comes as Apple expanded patches for an actively exploited security flaw in the WebKit browser engine (CVE-2024-23222, CVSS score: 8.8) to include its Apple Vision Pro headset. The fix is available in visionOS 1.0.2.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/02/cisa-warns-of-active-exploitation-of.html