ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

Google Warns Against Commercial Spyware Exploiting Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-4135
Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera)

CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists.

9.632% KEV PoC
  • Google Chromium GPU (GPU process component of the Chromium engine)
  • Google Chrome (Chromium-based browser)
  • Microsoft Edge (Chromium-based browser)
  • +1 more
mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown)
CVE-2022-42856
Type Confusion in Apple WebKit (Safari/iOS/macOS/tvOS), Actively Exploited

CVE-2022-42856 is a type confusion vulnerability (CWE-843) in Apple's WebKit web engine, addressed with improved state handling and affecting Safari, iPhone OS (iOS), iPadOS, macOS (Ventura) and tvOS. It is triggered when a user processes maliciously crafted web content, for example by visiting an attacker-controlled web page, in a WebKit-based browser or app. Successful exploitation may lead to arbitrary code execution on the affected device. Anyone running the affected Apple platforms below the December 2022 patch level (Safari 16.2, macOS Ventura 13.1, tvOS 16.2, iOS/iPadOS 15.7.2, iOS 16.1.2) was exposed, which effectively means most Apple users at the time of disclosure. Exploitation is confirmed: Apple reported the issue may have been actively exploited against iOS versions released before iOS 15.1, it was added to CISA KEV on 2022-12-14 (EPSS 8.5%, 95th percentile), and related reporting ties it to commercial spyware campaigns in Italy, Malaysia, Kazakhstan and the UAE.

Do: Update immediately to Safari 16.2, macOS Ventura 13.1, tvOS 16.2, and iOS/iPadOS 15.7.2 (for iOS 15-era devices) or iOS 16.1.2 (for iOS 16-era devices), or any later release; this is a CISA KEV entry whose required action is to apply vendor updates. Because the flaw was exploited as a zero-day against iOS versions before iOS 15.1 and is linked to commercial spyware campaigns, treat patching as urgent and verify that all managed and BYOD iPhones and iPads are on a fixed version; on iOS, all third-party browsers and most web-content apps use WebKit, so the OS update itself is the remediation rather than switching browsers.

8.89% KEV
  • Apple Safari All versions prior to 16.2 (macOS)
  • Apple iPhone OS (iOS) iOS 15 versions prior to 15.7.2 and iOS 16 versions prior to 16.1.2 (actively exploited against iOS releases before iOS 15.1)
  • Apple iPadOS All versions prior to 15.7.2
  • +2 more
mass~1 billion+ Apple devices at disclosure (every iOS/iPadOS/macOS/tvOS device below the December 2022 patch level; Apple's active installed base exceeds 1…
Full article408 words · extracted from infosecurity-magazine.com · click to collapse

Google’s Threat Analysis Group (TAG) has revealed tracking over 30 commercial spyware vendors that facilitate the spread of malware by government-backed threat actors.

Writing in a blog post published earlier today, TAG’s Clement Lecigne said these vendors are arming countries that would otherwise not be able to develop these tools.

“While the use of surveillance technologies may be legal under national or international laws, they are often found to be used by governments to target dissidents, journalists, human rights workers and opposition party politicians,” Lecigne wrote.

In particular, the post describes two highly targeted campaigns leveraging various zero-day exploits against Android, iOS and Chrome devices.

The first of them is based on an iOS remote code execution vulnerability (CVE-2022-42856) and a heap buffer overflow vulnerability in the Chrome web browser (CVE-2022-4135). The campaign relied on bit.ly links sent over SMS to potential victims in Italy, Malaysia and Kazakhstan.

On iOS devices, this campaign eventually delivers a payload pinging back the GPS location of the device. It also gives the attacker the ability to install an .IPA file (iOS application archive) onto the victim’s machine. The attack chain was similar on Android, with the main difference being that the attackers targeted phones with an ARM GPU running Chrome versions before 106.

The second campaign observed by TAG was discovered in December 2022. It relied on a complete exploit chain consisting of multiple zero-days and n-days targeting the latest version of the Samsung Internet Browser.

Read more on Samsung vulnerabilities here: Google Exposes 18 Zero-Day Flaws in Samsung Exynos Chips

“The link directed users to a landing page identical to the one TAG examined in the Heliconia framework developed by commercial spyware vendor Variston,” Lecigne explained. “The exploit chain ultimately delivered a fully featured Android spyware suite written in C++ that includes libraries for decrypting and capturing data from various chat and browser applications.”

The researcher added that the threat actor behind this second campaign targeted UAE users and may be a customer or partner of Variston, or otherwise working closely with them.

“The exploit chain TAG recovered was delivered to the latest version of Samsung’s Browser, which runs on Chromium 102 and does not include recent mitigations. If they had been in place, the attackers would have needed additional vulnerabilities to bypass the mitigations,” Lecigne said.

Google confirmed it reported these vulnerabilities to the vendors, who promptly issued patches for all of them.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/google-warns-spyware-zero-days/