ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hackers Exploit macOS Zero-Day to Hack Hong Kong Users with new Implant

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-30869CVE-2021-1789CVE-2019-8506

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-8506
Type Confusion in Apple WebKit (Safari, iOS, iCloud, iTunes) Allows Code Execution

CVE-2019-8506 is a type confusion flaw (CWE-843) in the web content processing engine shared by Apple's Safari browser and the iOS, tvOS, and watchOS operating systems, as well as iTunes and iCloud for Windows. It is triggered when a user processes maliciously crafted web content, such as by visiting an attacker-controlled webpage. Successful exploitation may allow the attacker to execute arbitrary code on the affected device or desktop. Anyone running Safari or iOS/tvOS versions before 12.2, watchOS before 5.2, or iTunes/iCloud for Windows before the fixed 12.9.4/7.11 releases is affected, and Red Hat Enterprise Linux (Desktop, Server, Workstation) is also listed among affected products in the source data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-04, indicating known exploitation in the wild, though no public PoC is available and ransomware use is unknown.

Do: Upgrade affected Apple software to the fixed releases: iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, and iCloud for Windows 7.11, or later versions. Inventory Windows endpoints for iTunes and iCloud installations, which are frequently overlooked, and update or remove them. Red Hat Enterprise Linux users should apply Red Hat's updates addressing this CVE, and because this is a CISA KEV entry, patch per vendor instructions promptly.

8.818% KEV
  • apple iPhone OS (iOS) prior to 12.2
  • apple tvOS prior to 12.2
  • apple watchOS prior to 5.2
  • +4 more
mass≈1 billion+ users/devices
CVE-2021-1789
Type Confusion RCE in Apple WebKit (iOS, macOS, Safari, tvOS, watchOS)

CVE-2021-1789 is a type confusion flaw (CWE-843) in the WebKit engine that powers Safari and web views across Apple's platforms, fixed through improved state handling. An attacker triggers it by getting a victim to open or view maliciously crafted web content, for example via a crafted link in an email or a compromised webpage. Successful exploitation leads to arbitrary code execution in the context of the application rendering the content, and the CVSS 3.1 score of 8.8 reflects high confidentiality, integrity and availability impact with network attack vector and user interaction required. Everyone running affected Apple software below the February 2021 patch levels is exposed — iOS/iPadOS before 14.4, macOS Big Sur before 11.2, macOS Catalina/Mojave without Security Update 2021-001, tvOS before 14.4, watchOS before 7.3, and Safari before 14.0.3 — as well as WebKitGTK users on Fedora per the CPE data. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2022-05-04) and was used as a macOS zero-day in watering-hole attacks on Hong Kong pro-democracy users, deploying the DazzleSpy backdoor; EPSS estimates a 14.5% chance of exploitation in the next 30 days.

Do: Update to iOS/iPadOS 14.4, macOS Big Sur 11.2 (or apply Security Update 2021-001 on Catalina/Mojave), Safari 14.0.3, tvOS 14.4 and watchOS 7.3; on Fedora, apply the available webkitgtk package update. Because this flaw is in CISA KEV and used in targeted watering-hole attacks, prioritize patching internet-facing and high-risk user fleets. Confirm inventory shows no Apple devices below these patch levels and that users are not relying on outdated Safari builds on unsupported macOS versions.

8.814% KEV
  • apple iOS prior to 14.4
  • apple iPadOS prior to 14.4
  • apple macOS Big Sur prior to 11.2
  • +7 more
masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch) plus WebKitGTK-based Linux browsers/apps
CVE-2021-30869
Type Confusion in Apple iOS, iPadOS and macOS Allows Kernel Code Execution

CVE-2021-30869 is a type confusion flaw (CWE-843) in the kernel of Apple's iOS, iPadOS, and macOS operating systems, addressed with improved state handling. It is triggered locally when a user runs a malicious application, which can then leverage the memory-type confusion to escape the app sandbox context. Successful exploitation gives the attacker arbitrary code execution with kernel privileges, effectively full control of the device. Users of iPhone, iPad, and Mac running versions released before the January 2021 fixes are affected. Apple has confirmed exploits exist in the wild, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and news reporting linked exploitation to targeted attacks against macOS users in Hong Kong.

Do: Upgrade to iOS 14.4 (or iOS 12.5.5 for older devices), iPadOS 14.4, or macOS Big Sur 11.2, and apply Security Update 2021-001 Catalina or Security Update 2021-001 Mojave (Security Update 2021-006 Catalina also addresses the issue) on Macs. Because exploitation requires running a malicious application, remove untrusted apps and warn users against installing software from unverified sources while patching. This flaw is on the CISA KEV list, so federal and KEV-committed organizations must apply the updates per vendor instructions; no public proof-of-concept is known.

7.84% KEV
  • Apple iPhone OS (iOS) iOS versions prior to 14.4; iOS 12.x prior to 12.5.5
  • Apple iPadOS iPadOS versions prior to 14.4
  • Apple macOS Big Sur macOS Big Sur versions prior to 11.2
  • +2 more
masshundreds of millions of devices (Apple's active installed base of iPhones, iPads, and Macs is on the order of 1 billion devices, and pre-patch OS versions were…
Full article490 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 12, 2021

Google researchers on Thursday disclosed that it found a watering hole attack in late August exploiting a now-patched zero-day in macOS operating system and targeting Hong Kong websites related to a media outlet and a prominent pro-democracy labor and political group to deliver a never-before-seen backdoor on compromised machines.

"Based on our findings, we believe this threat actor to be a well-resourced group, likely state backed, with access to their own software engineering team based on the quality of the payload code," Google Threat Analysis Group (TAG) researcher Erye Hernandez said in a report.

Tracked as CVE-2021-30869 (CVSS score: 7.8), the security shortcoming concerns a type confusion vulnerability affecting the XNU kernel component that could cause a malicious application to execute arbitrary code with the highest privileges.

Apple originally addressed the issue for macOS Big Sur devices as part of a security update shipped on February 1, only to follow it up with a standalone update aimed at macOS Catalina devices on September 23 following reports of in-the-wild exploitation — a gap of 234 days between the two patches — underscoring a case of how inconsistencies in resolving a vulnerability across different versions of the operating system can be exploited by threat actors to their advantage.

The attacks observed by TAG involved an exploit chain that strung together CVE-2021-1789, a remote code execution bug in WebKit that was fixed in February 2021, and the aforementioned CVE-2021-30869 to break out of the Safari sandbox, elevate privileges, and download and execute a second stage payload dubbed "MACMA" from a remote server.

This previously undocumented malware, a fully-featured implant, is marked by "extensive software engineering" with capabilities to record audio and keystrokes, fingerprint the device, capture the screen, download and upload arbitrary files, and execute malicious terminal commands, Google TAG said. Samples of the backdoor uploaded to VirusTotal reveal that none of the anti-malware engines currently detect the files as malicious.

According to security researcher Patrick Wardle, a 2019 variant of MACMA masquerades as Adobe Flash Player, with the binary displaying an error message in Chinese language post-installation, suggesting that "the malware is geared towards Chinese users" and that "this version of the malware is designed to be deployed via socially engineering methods." The 2021 version, on the other hand, is designed for remote exploitation.

The websites, which contained malicious code to serve exploits from an attacker-controlled server, also acted as a watering hole to target iOS users, albeit using a different exploit chain delivered to the victims' browser. Google TAG said it was only able to recover a part of the infection flow, where a type confusion bug (CVE-2019-8506) was used to gain code execution in Safari.

Additional indicators of compromise (IoCs) associated with the campaign can be accessed here.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/11/hackers-exploit-macos-zero-day-to-hack.html