New 'unc0ver' Tool Can Jailbreak All iPhone Models Running iOS 11.0
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-9859 | Double-Free Kernel Flaw Allows Code Execution on Apple iOS, macOS, tvOS, watchOS CVE-2020-9859 is a memory handling flaw in the kernels of Apple's operating systems (classified as CWE-415, a double free), addressed through improved memory handling by Apple. It is triggered by an application running on the device, and the local attack vector requires no user interaction. A successful exploit allows arbitrary code execution with kernel privileges, giving the attacker near-complete control of the affected device. Users of iPhone (iOS), iPad (iPadOS), Macs running macOS Catalina 10.15, Apple TV (tvOS), and Apple Watch (watchOS) on versions prior to the fixes are affected. The flaw was reported as a zero-day fixed by Apple and is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and it is associated in public reporting with the unc0ver jailbreak, though no public proof-of-concept is known. Do: Update to iOS/iPadOS 13.5.1 or later, apply the macOS Catalina 10.15.5 Supplemental Update, and update Apple TV (tvOS 13.4.6 or later) and Apple Watch (watchOS 6.2.6 or later), per the vendor's instructions as required by CISA KEV. Because this is a local privilege escalation, prioritize patching fleet devices where untrusted apps may run, and check for devices unable to upgrade (older iPhones/iPads, Apple TVs and watches stuck on pre-fix versions) as residual risk. | 7.8 | <1% | KEV |
| masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch install base at the time of disclosure) | |
| CVE-2021-1782 | Race Condition Privilege Escalation in Apple iOS, macOS, watchOS, and tvOS A race condition caused by improper locking (CWE-667) in Apple's operating systems could allow local privilege escalation. The flaw is triggered by a malicious application already running on the device that exploits a timing race; exploitation requires only low local privileges and no user interaction, though the attack complexity is rated high. A successful attacker gains elevated privileges with high impact to the confidentiality, integrity, and availability of the device. Users of iPhone, iPad, Mac, Apple Watch, and Apple TV running versions earlier than iOS/iPadOS 14.4, macOS Big Sur 11.2 (or the 2021-001 security updates for Catalina and Mojave), watchOS 7.3, and tvOS 14.4 are affected. Apple reported the issue as actively exploited in the wild, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and no public proof-of-concept is known. Do: Upgrade to iOS/iPadOS 14.4, watchOS 7.3, and tvOS 14.4; on Macs, upgrade to macOS Big Sur 11.2 or apply Security Update 2021-001 for Catalina and Mojave. As an interim mitigation, avoid installing untrusted applications, since exploitation requires a malicious local app. This vulnerability is in the CISA KEV catalog, so organizations subject to the required action should verify that all managed Apple devices are running the patched versions. | 7.0 | 2% | KEV |
| masshundreds of millions of Apple devices (estimate based on Apple's active installed base exceeding 1 billion devices) |
Full article406 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 02, 2021
A popular jailbreaking tool called "unc0ver" has been updated to support iOS 14.3 and earlier releases, thereby making it possible to unlock almost every single iPhone model using a vulnerability that Apple in January disclosed was actively exploited in the wild.
The latest release, dubbed unc0ver v6.0.0, was released on Sunday, according to its lead developer Pwn20wnd, expanding its compatibility to jailbreak any device running iOS 11.0 through iOS 14.3 using a kernel vulnerability, including iOS 12.4.9-12.5.1, 13.5.1-13.7, and 14.0-14.3.
Tracked as CVE-2021-1782, the flaw is a privilege escalation vulnerability in the kernel stemming from a race condition that could cause a malicious application to elevate its privileges.
"We wrote our own exploit based on CVE-2021-1782 for #unc0ver to achieve optimal exploit speed and stability," Pwn20wnd said in a separate tweet.
The vulnerability has since been addressed by Apple as part of its iOS and iPadOS 14.4 updates released on January 26, 2021, but not before admitting that the issue may have been under active attack by bad actors.
The iPhone maker, however, did not disclose how widespread the attack was or reveal the identities of the attackers actively exploiting them.
Jailbreaking, similar to rooting on Google's Android, involves a privilege escalation that works by exploiting flaws in iOS to grant users root access and full control over their devices. In doing so, it allows iOS users to remove software restrictions imposed by Apple, thereby allowing access to additional customization and otherwise prohibited apps.
For its part, Apple has steadily made it difficult to jailbreak devices by locking down its hardware and software for security reasons, which it says helps counter malware attacks.
ZecOps CEO Zuk Avraham said the jailbreak is "yet another example that attackers have an edge on iOS vs. defenders," adding "[Apple] needs to stop the need to jailbreak the device in the first place and should just enable users to have full access without a need to run an exploit."
Last May, the unc0ver team released a similar jailbreak for iPhones running iOS 11 to iOS 13.5 by exploiting a memory consumption issue in the kernel (CVE-2020-9859). But it was patched by Apple in a matter of days with the release of iOS 13.5.1 to prevent the vulnerability from being exploited maliciously.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/03/new-unc0ver-tool-can-jailbreak-all.html