ZeroHour
CyberScooppublished ()ingested @AJVicens

Apple issues third mobile OS update after zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-38606CVE-2023-32434CVE-2023-32435

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-32435
+1 in the same advisory: …32434
Memory Corruption in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-32435 is an out-of-bounds write (CWE-787) memory corruption flaw in the WebKit engine shipped with Apple Safari, iOS, iPadOS, and macOS. It is triggered when WebKit processes maliciously crafted web content, such as a hostile webpage or embedded HTML, and successful exploitation leads to arbitrary code execution. Because WebKit is also used by non-Apple HTML parsers and applications, the impact extends beyond Safari and Apple's own browsers. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-06-23, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. EPSS estimates a 22.8% probability of exploitation in the next 30 days (98th percentile), and a CVSS score is not yet published.

Do: Update Safari to 16.5 or later, iOS/iPadOS to 16.5 (or 15.7.6 on the legacy branch) or later, and macOS to the patched Ventura/Monterey/Big Sur releases (13.4 / 12.6.6 / 11.7.7) or later, then verify managed fleets are on fixed builds per the CISA KEV required action. Prioritize internet-exposed and high-risk users, since the flaw is confirmed exploited in the wild. If you ship or operate non-Apple products that embed WebKit, pull the fixed WebKit from the upstream project or your vendor.

8.8
group max
23% KEV
  • Apple Safari Versions prior to the WebKit fix shipped in Safari 16.5 (May 2023; see Apple advisory for exact ranges)
  • Apple iOS Versions prior to iOS 16.5 and the iOS 15.7.6 legacy-branch update
  • Apple iPadOS Versions prior to iPadOS 16.5 and the iPadOS 15.7.6 legacy-branch update
  • +2 more
mass>1,000,000,000 devices/users (WebKit is the system HTML engine on every iPhone and iPad and powers Safari on macOS)
CVE-2023-38606
Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS

CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected.

Do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines.

5.53% KEV
  • apple iPhone OS (iOS) iOS versions prior to iOS 15.7.8 and iOS 16 versions prior to iOS 16.6 (fixed in iOS 15.7.8 and iOS 16.6)
  • apple iPadOS iPadOS versions prior to 15.7.8 and iPadOS 16 versions prior to 16.6 (fixed in iPadOS 15.7.8 and iPadOS 16.6)
  • apple macOS Big Sur versions prior to 11.7.9 (fixed in macOS Big Sur 11.7.9)
  • +4 more
mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023)
Full article687 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The patch is the latest to address issues associated with what cybersecurity firm Kaspersky called Operation Triangulation.

The Apple Inc logo is displayed outside a retail store at the Third Street Promenade in Santa Monica, California on March 20, 2023. (Photo by PATRICK T. FALLON/AFP via Getty Images)

Apple on Monday issued its third security update in roughly a month to remedy vulnerabilities exploited in Operation Triangulation, a spyware campaign that researchers say specifically targeted iMessage users in Russia.

The Russian arm of cybersecurity firm Kaspersky on June 1 revealed the details of a zero-click iOS exploit. The company’s researchers said they discovered it while monitoring the company’s own corporate Wi-Fi network dedicated to mobile devices. The findings were released the same day Russia’s Federal Security Service, or FSB, said it had uncovered an American espionage operation targeting Apple devices in Russia in cooperation with Apple.

Apple told CyberScoop at the time that had “never worked with any government to insert a backdoor into any Apple product and never will.”

Kaspersky has not attributed the campaign.

Monday’s security patch addressed a vulnerability tracked as CVE-2023-38606 and had been actively exploited against versions of Apple’s mobile operating system before version 15.7.1, the company said in the notice, an iteration of the operating system that was replaced with the release of iOS 16 in September 2022.

“Apple has addressed one more kernel vulnerability discovered by Kaspersky researchers during the investigation of the Operation Triangulation attack,” the company said in an emailed statement Tuesday. “This zero-day vulnerability CVE-2023-38606 was part of the discovered zero-click exploit chain. It affected a wide range of Apple products – iPhones, iPods, iPads, macOS devices, Apple TV and Apple Watch. Patching is available as part of the Apple Security Updates release as of July 24, 2023, and we highly recommend users to update their devices.”

Previous patches associated with Operation Triangulation address vulnerabilities tracked as CVE-2023-32434 and CVE-2023-32435. The patch was one of eight security updates issued Monday.

Phil Stokes, a threat researcher with SentinelLabs, said in an email that Apple’s update concerns a bug that affects both macOS and iOS “but has only been reported as exploited in the wild against iOS devices to date.” His team is not aware of any of the malware or exploits being used aside from public reporting he said, but Apple users should update their operating systems as part of a wider security strategy.

“In the larger context, the number and timing of these updates suggest that investigation into Operation Triangulation is still ongoing and we are likely to see more details unfold in the near future,” Stokes added. “It is certainly unusual to see Apple roll out repeated patches in such a short space of time to address vulnerabilities related to one particular threat campaign.”

Updated July 25, 2023: This story has been updated to include comment from Kaspersky and Phil Stokes.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-os-update-spyware/