Apple Releases Urgent Security Patches For Zero‑Day Bugs Under Active Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-30661 | Use-After-Free in Apple WebKit Enables Code Execution via Malicious Web Content CVE-2021-30661 is a use-after-free flaw (CWE-416) in the storage handling of Apple's WebKit browser engine, affecting Safari, iOS, iPadOS, macOS, watchOS and tvOS. It is triggered simply by processing maliciously crafted web content, such as a victim loading a hostile web page, with no privileges or authentication required beyond user interaction. A successful attack can lead to arbitrary code execution on the affected device, with confidentiality, integrity and availability all rated high. Anyone running builds older than the fixed versions (Safari 14.1, iOS 12.5.3/14.5, iPadOS 14.5, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5) is potentially affected. Apple disclosed that the issue was actively exploited at the time of patching; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and EPSS assigns a roughly 4.5% probability of exploitation in the next 30 days. Do: Apply Apple's updates per vendor instructions: Safari 14.1, iOS 14.5/iPadOS 14.5 (or iOS 12.5.3 for older devices that cannot run iOS 14), macOS Big Sur 11.3, watchOS 7.4 and tvOS 14.5. Because the bug was exploited in the wild and is on CISA's KEV list, treat these patches as urgent and prioritize browsers and user workstations; verify that legacy devices still running pre-12.5.3 or pre-14.5 iOS builds are found and updated. No public proof-of-concept is known and patching is the primary mitigation. | 8.8 | 4% | KEV |
| masshundreds of millions to over a billion Apple devices across iOS, iPadOS, macOS, Safari, watchOS and tvOS (order-of-magnitude estimate) | |
| CVE-2021-30666 | WebKit Buffer Overflow in Apple iOS Allows Code Execution via Malicious Web Content CVE-2021-30666 is a buffer overflow (CWE-119) in the WebKit web engine on Apple iOS, caused by improper memory handling. It is triggered remotely when the device processes maliciously crafted web content, meaning a victim only has to encounter attacker-controlled web pages or web content for the flaw to be reached (network vector with user interaction, per the CVSS 3.1 score of 8.8). Successful exploitation can lead to arbitrary code execution on the device with full confidentiality, integrity, and availability impact. All iOS devices running versions before the iOS 12.5.3 fix are affected, with iOS 12.5.3 serving devices that remain on Apple's legacy iOS 12 branch. Apple reported the bug was being actively exploited in the wild when it was patched, CISA added it to the KEV on 2021-11-03, and EPSS assigns a 3% probability of exploitation within 30 days (87th percentile), though no public PoC is known. Do: Upgrade affected devices to iOS 12.5.3 or later, and have devices on newer iOS branches take the corresponding current-branch iOS security updates Apple released at the same time, per CISA's required action to apply updates per vendor instructions. Because the attack vector is web content and no public workaround is documented, patching WebKit is the primary defense, so prioritize older hardware that only receives iOS 12.5.x updates and verify fleet-wide compliance. | 8.8 | 3% | KEV |
| masshundreds of millions of iOS devices (global iPhone install base exceeds 1 billion; devices limited to the legacy iOS 12 branch are in the tens of millions) |
Full article410 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 04, 2021
Apple on Monday released security updates for iOS, macOS, and watchOS to address three zero-day flaws and expand patches for a fourth vulnerability that the company said might have been exploited in the wild.
The weaknesses all concern WebKit, the browser engine which powers Safari and other third-party web browsers in iOS, allowing an adversary to execute arbitrary code on target devices. A summary of the three security bugs are as follows -
- CVE-2021-30663: An integer overflow vulnerability that could be exploited to craft malicious web content, which may lead to code execution. The flaw was addressed with improved input validation.
- CVE-2021-30665: A memory corruption issue that could be exploited to craft malicious web content, which may lead to code execution. The flaw was addressed with improved state management.
- CVE-2021-30666: A buffer overflow vulnerability that could be exploited to craft malicious web content, which may lead to code execution. The flaw was addressed with improved memory handling.
The development comes a week after Apple rolled out iOS 14.5 and macOS Big Sur 11.3 with a fix for a potentially exploited WebKit Storage vulnerability. Tracked as CVE-2021-30661, the use-after-free issue was discovered and reported to the iPhone maker by a security researcher named yangkang (@dnpushme) of Qihoo 360 ATA.
yangkang, along with zerokeeper and bianliang, have been credited with reporting the three new flaws.
It's worth noting that CVE-2021-30666 only affects older Apple devices such as iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation). The iOS 12.5.3 update, which remediates this flaw, also includes a fix for CVE-2021-30661.
The company said it's aware of reports that the issues "may have been actively exploited" but, as is typically the case, failed to elaborate about the nature of attacks, the victims that may have been targeted, or the threat actors that may be abusing them.
Users of Apple devices are recommended to update to the latest versions to mitigate the risk associated with the flaws.
Update: Apple has also released a new version of Safari 14.1 for macOS Catalina and macOS Mojave, with the update introducing fixes for the two WebKit flaws CVE-2021-30663 and CVE-2021-30665. The update comes a day after patches were shipped for iOS, macOS, and watchOS.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/05/apple-releases-urgent-security-patches.html