Apple and Google Launch Cross-Platform Feature to Detect Unwanted Bluetooth Tracking Devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-23296 | Kernel Memory Corruption in Apple iOS, iPadOS, macOS, tvOS, watchOS, visionOS CVE-2024-23296 is a memory corruption issue (CWE-787, out-of-bounds write) in the kernels of Apple's operating systems, addressed by Apple with improved validation in its March 2024 updates. Per Apple and the CVSS vector (AV:L/PR:L/UI:N), exploitation is local with low privileges and no user interaction: an attacker who has already gained arbitrary kernel read and write capability can use the flaw to bypass kernel memory protections, meaning it is typically used in an exploit chain after an initial kernel compromise. Successful abuse defeats hardened kernel memory restrictions, potentially giving the attacker broader control over the operating system and undermining kernel-level protections. Anyone running affected versions is exposed: iPhone/iPad on iOS/iPadOS prior to the 17.4 and 16.7.8 fixes, Macs prior to macOS Sonoma 14.4, Ventura 13.6.7 or Monterey 12.7.6, Apple TV prior to tvOS 17.4, Apple Watch prior to watchOS 10.4, and Vision Pro prior to visionOS 1.1. Apple has stated the issue may have been exploited in the wild, and CISA added it to the KEV catalog on 2024-03-06; no public proof-of-concept is known and ransomware use is unknown (EPSS 1.4%, 71st percentile). Do: Patch immediately to iOS/iPadOS 17.4 (or 16.7.8 for devices staying on iOS 16), macOS Sonoma 14.4 / Ventura 13.6.7 / Monterey 12.7.6, tvOS 17.4, watchOS 10.4 and visionOS 1.1; no workaround is documented, and CISA's KEV required action mandates applying vendor fixes (or discontinuing use) for federal agencies. Because the flaw is used to bypass kernel memory protections after an attacker already has kernel read/write, also ensure devices are current on all other Apple kernel security updates and inventory for any Apple phones, tablets, Macs or TVs running older OS versions. | 7.8 | 1% | KEV |
| masshundreds of millions of devices (Apple's active installed base exceeds 2 billion devices; affected iOS/macOS/tvOS/watchOS versions were current for most users… | |
| CVE-2024-27818 +1 in the same advisory: …27804 | The issue was addressed with improved memory handling. The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution. NVD description · AI analysis pending | 7.8 group max | <1% |
| — |
Full article599 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 14, 2024Location Tracking / Privacy
Apple and Google on Monday officially announced the rollout of a new feature that notifies users across both iOS and Android if a Bluetooth tracking device is being used to stealthily keep tabs on them without their knowledge or consent.
"This will help mitigate the misuse of devices designed to help keep track of belongings," the companies said in a joint statement, adding it aims to address "potential risks to user privacy and safety."
The proposal for a cross-platform solution was originally unveiled exactly a year ago by the two tech giants.
The capability – dubbed "Detecting Unwanted Location Trackers" (DULT) – is available in Android devices running versions 6.0 and later, and iOS devices with iOS 17.5, which was officially shipped yesterday.
As part of the industry specification, Android users will receive a "Tracker traveling with you" alert if an unidentified Bluetooth tracking device is detected as moving along with them over time, irrespective of the platform it's paired with. On iOS, users will get an "[Item] Found Moving With You" message.
Regardless of the operating system, users who receive such an alert have the option to view the tracker's identifier, play a sound to help locate it, and access instructions to disable it.
"This cross-platform collaboration — also an industry first, involving community and industry input — offers instructions and best practices for manufacturers, should they choose to build unwanted tracking alert capabilities into their products," the companies said.
The development comes in response to reports that trackers like AirTags are being used by bad actors for malicious or criminal purposes, often abused as a nefarious tracking tool by domestic abusers to stalk their targets.
A class-action lawsuit filed against Apple in October 2023 alleged that AirTags have become "one of the most dangerous and frightening technologies employed by stalkers" and that they can be used to determine "real-time location information to track victims."
Last year, a group of researchers from Johns Hopkins University and the University of California, San Diego, devised a cryptographic scheme that offers a better trade-off between user privacy and stalker detection through a mechanism called multi-dealer secret sharing (MDSS).
"MDSS extends standard secret sharing to admit multiple dealers with multiple secrets while achieving new properties of unlinkability and multi-dealer correctness," the academics said in a paper titled "Abuse-Resistant Location Tracking: Balancing Privacy and Safety in the Offline Finding Ecosystem."
Apple Backports Fix for CVE-2024-23296
The DULT announcement also follows Apple's decision to backport a fix released in March 2024 for a security flaw in the RTKit real-time operating system (CVE-2024-23296) to devices running older versions of iOS, iPadOS, and macOS.
The vulnerability, which allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections, has come under active exploitation in the wild, although technical specifics on the nature of these attacks are presently unknown.
Patches for the shortcoming are available in the following versions -
- iOS 16.7.8 and iPadOS 16.7.8 - iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation
- macOS Ventura 13.6.7 - Macs running macOS Ventura
Apple's iOS 17.5 update also remediates a total of 15 security vulnerabilities, including flaws in AppleAVD (CVE-2024-27804) and the kernel (CVE-2024-27818) that could be exploited to cause unexpected app termination or arbitrary code execution. The same two flaws have been resolved in macOS Sonoma 14.5.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/apple-and-google-launch-cross-platform.html