ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple patches two zero-days under attack (CVE-2023-41064, CVE-2023-41061)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41061
Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS

Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11.

Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds.

7.84% KEV
  • Apple iPhone OS (iOS) all versions prior to 16.6.1
  • Apple iPadOS all versions prior to 16.6.1
  • Apple watchOS all versions prior to 9.6.2
massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched)
CVE-2023-41064
ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution

CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs.

Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices.

7.845% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion)
Full article418 words · extracted from helpnetsecurity.com · click to collapse

Apple has patched two zero-day vulnerabilities (CVE-2023-41064, CVE-2023-41061) exploited to deliver NSO Group’s Pegasus spyware.

CVE-2023-41064 CVE-2023-41061

“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab shared.

“The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim.”

About the vulnerabilities

CVE-2023-41064 is a buffer overflow vulnerability in the ImageI/O framework, which allows applications to read and write most image file formats. The vulnerability can be triggered with a maliciously crafted image and can lead to arbitrary code execution.

CVE-2023-41061 is a validation issue in Apple’s Wallet, where users can store payment cards, IDs, event tickets, traveling tickets, etc. The vulnerability can be triggered with a maliciously crafted attachment and can lead to arbitrary code execution.

CVE-2023-41064 was reported by The Citizen Lab at The University of Torontoʼs Munk School, while CVE-2023-41061 was figured out by Apple with their help, probably as they were validating the existence of CVE-2023-41064.

Both have been fixed in the iOS 16 branch. A fix for CVE-2023-41064 is also included in the latest security update for macOS Ventura (13.5.2), and for CVE-2023-41061 in watchOS 9.6.2.

The patches will likely be backported to older iOS, iPadOS and macOS branches soon.

An exploit chain to target high-risk users

The exploit chain – dubbed BLASTPASS by Citizen Lab – was detected when they analyzed a device of an individual employed by a Washington DC-based civil society organization with international offices.

“This latest find shows once again that civil society is targeted by highly sophisticated exploits and mercenary spyware,” they said. “We expect to publish a more detailed discussion of the exploit chain in the future.”

“Regular” users are advised to update their devices as soon as possible, but users who are at risk of highly targeted cyberattacks with spyware like Pegasus should think about activating Lockdown Mode.

“We believe, and Apple’s Security Engineering and Architecture team has confirmed to us, that Lockdown Mode blocks this particular attack,” the Citizen Lab pointed out.

Another good idea for users that run the latest versions of Apple’s operating systems is to enable Apple Rapid Security Response, which automatically installs security patches as they are made available.

UPDATE (September 12, 2023, 04:30 a.m. ET):

Apple has fixed CVE-2023-41064 in older operating systems: iOS 15.7.9 and iPadOS 15.7.9, macOS Monterey 12.6.9 and macOS Big Sur 11.7.10.

CISA has added the two flaws to its KEV catalog.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/09/08/cve-2023-41064-cve-2023-41061/