ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds bugs in Chrome and macOS to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-8526CVE-2023-2033

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-8526
Use-After-Free Local Privilege Escalation in Apple macOS

CVE-2019-8526 is a use-after-free (CWE-416) memory-corruption flaw in Apple macOS that can be triggered by a low-privileged application already running on the target Mac, with no user interaction required. Successful exploitation lets an attacker gain elevated privileges beyond those of the triggering application, making it a local privilege escalation vector that is typically chained with other flaws. The issue is fixed in macOS Mojave 10.14.4, so users and organizations running earlier macOS builds are affected. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2023-04-17, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. Related reporting on macOS watering-hole attacks delivering the DazzleSpy backdoor underscores active macOS targeting, but the provided data does not confirm a direct link to this specific CVE.

Do: Upgrade affected Macs to macOS Mojave 10.14.4 or a later macOS release per Apple's instructions (CISA's required action), and inventory for any machines stuck on older builds using About This Mac or 'sw_vers -productVersion'. Because the flaw requires local execution, prioritize multi-user, shared, or high-risk Macs. Given confirmed in-the-wild exploitation, hunt for signs of post-exploitation on previously unpatched systems, keeping in mind macOS backdoor campaigns (e.g., DazzleSpy) reported against Mac users.

7.8<1% KEV
  • Apple macOS (Mac OS X) macOS versions prior to macOS Mojave 10.14.4 (fix shipped in macOS Mojave 10.14.4; CISA scope: Apple macOS)
massmacOS install base exceeds 100M active devices; likely millions of Macs were, or remain, on vulnerable pre-10.14.4 builds
CVE-2023-2033
Type Confusion in Google Chromium V8 Engine Exploited in the Wild

CVE-2023-2033 is a type confusion flaw (CWE-843) in Google's Chromium V8 JavaScript engine that a remote attacker can trigger by convincing a user to load a crafted HTML page. Successful exploitation could lead to heap corruption in the browser, potentially allowing the attacker to execute code in the context of the affected browser. Because V8 underpins the entire Chromium ecosystem, users of Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browser or application are potentially affected. The flaw is already being exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-17, and EPSS assigns a 40.8% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known and ransomware use is unknown.

Do: Update Google Chrome and every other Chromium-based browser in use (Microsoft Edge, Opera, Brave, etc.) to the latest vendor-supplied stable release, per CISA's KEV required action to apply updates per vendor instructions. Verify installed browser versions across managed endpoints and treat unpatched Chromium builds as actively exploited given the KEV listing and high EPSS score.

8.841% KEV
  • Google Chromium V8 engine
  • Google Chrome (Chromium-based browser)
  • Microsoft Edge (Chromium-based browser)
  • +1 more
massbillions of users (Chrome alone has roughly 3 billion users; Chromium also powers Edge, Opera, Brave and many embedded applications)
Full article291 words · extracted from securityaffairs.com · click to collapse

US Cybersecurity and Infrastructure Security Agency (CISA) added Chrome and macOS vulnerabilities to its Known Exploited Vulnerabilities catalog.

U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the following five new issues to its Known Exploited Vulnerabilities Catalog:

  • CVE-2019-8526 – Apple macOS Use-After-Free Vulnerability. The CVE-2019-8526 flaw has been exploited by the DazzleSpy backdoor in watering hole attacks aimed at politically active individuals in Hong Kong. The issue was used to dump iCloud Keychain if the macOS version is lower than 10.14.4.
  • CVE-2023-2033 – Google Chromium V8 Engine Type Confusion Vulnerability. The CVE-2023-2033 flaw is the first Chrome zero-day vulnerability addressed by Google in 2023. The vulnerability was reported by Clément Lecigne of Google’s Threat Analysis Group on 2023-04-11. Google did not disclose details of the attacks exploiting this vulnerability, it will not provide bug details and links until a majority of users will have updated their installs.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this flaw by May 8, 2023.

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:

  • The Teacher – Most Educational Blog
  • The Entertainer – Most Entertaining Blog
  • The Tech Whizz – Best Technical Blog
  • Best Social Media Account to Follow (@securityaffairs)

Please nominate Security Affairs as your favorite blog.

Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144967/security/cisa-chrome-macos-known-exploited-vulnerabilities-catalog.html