Update your Mac OS X — Apple has released Important Security Updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-4654 | IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2016-4656 +1 in the same advisory: …4655 | Kernel Memory Corruption in Apple iOS Enables Privileged Code Execution CVE-2016-4656 is a memory corruption flaw in the Apple iOS kernel (CWE-264, permissions/privilege handling) that can be triggered by a crafted or untrusted application running on the device. A successful exploit lets the attacker execute arbitrary code in the privileged kernel context, effectively giving full control of the device, or alternatively crash it to cause a denial of service. Any iPhone, iPad or iPod touch running an iOS version before the August 2016 fix, iOS 9.3.5, is affected. The flaw is confirmed exploited in the wild: it was one of the 'Trident' chain used in the 2016 Pegasus spyware attacks (chained with the WebKit flaw CVE-2016-4657, delivered via malicious links), and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-24; EPSS of ~24% (98th percentile) indicates continued exploitation risk. Do: Update all iPhones, iPads and iPod touches to iOS 9.3.5 or later (or any currently supported iOS/iPadOS release) per the CISA-required action; there is no reliable workaround for a kernel memory-corruption flaw. Inventory for legacy devices that cannot upgrade beyond iOS 9.3.4 or earlier and retire or isolate them, and since this bug was used in targeted Pegasus spyware campaigns, review high-risk or targeted users' devices for signs of compromise. | 7.8 group max | 24% | KEV PoC |
| masshundreds of millions of iOS devices at disclosure (of Apple's ~1 billion active-device install base in 2016); remaining unpatched legacy devices today likely… |
Full article453 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalSep 02, 2016
If you own a Mac laptop or desktop, you need to update your system right now.
It turns out that the critical zero-day security vulnerabilities disclosed last week, which targeted iPhone and iPad users, affect Mac users as well.
Late last week, Apple rolled out iOS 9.3.5 update to patch a total of three zero-day vulnerabilities that hackers could have used to remotely gain control of an iPhone by simply making the victim click a link.
Dubbed "Trident," the security holes were used to create spyware (surveillance malware) called 'Pegasus' that was apparently used to target human rights activist Ahmed Mansoor in the United Arab Emirates.
Pegasus could allow an attacker to access an incredible amount of data on a target victim, including text messages, calendar entries, emails, WhatsApp messages, user's location, microphone.
Pegasus Spyware could even allow an attacker to fully download victim's passwords and steal the stored list of WiFi networks, as well as passwords the device connected to.
Apple is now patching the same "Trident" bugs in Safari web browser on its desktop operating system, with urgent security updates for Safari 9 as well as OS X Yosemite and OS X El Capitan.
However, this is not a surprise because iOS and OS X, and mobile and desktop version of Safari browser share much of the same codebase. Therefore, zero-days in Apple’s iOS showed up in OS X as well.
Pegasus exploit takes advantage of Trident bugs to remotely jailbreak and install a collection of spying software onto a victim's device, without the user’s knowledge.
One of the key tools of the exploit takes advantage of a memory corruption bug in Safari WebKit, allowing hackers to deliver the malicious payload when a target victim clicks on a malicious link and initiate the process of overtaking the operating system.
In an advisory, Apple warned that visiting a "maliciously crafted website" via Safari browser could allow attackers to execute arbitrary code on a victim's computer.
The patch updates that Apple released on Thursday fix the nasty Trident bugs, including CVE-2016-4654, CVE-2016-4655, and CVE-2016-4656, which were initially discovered and reported by mobile security startup Lookout and the University of Toronto’s Citizen Lab.
Based on a link sent to UAE human rights activist Ahmed Mansoor, Lookout Security, and Citizen Lab traced the three programming blunders and its Pegasus spyware kit to Israeli "cyber war" organization NSO Group, which sells hacking exploits to governments like the UAE.
Users can install security patches for Safari, El Capitan, and Yosemite via the usual software update mechanisms.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2016/09/apple-mac-os-x-update.html