ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes actively exploited vulnerabilities affecting older iDevices

criticalVulnerability exploited in the wildimportance 60CVE-2021-30761CVE-2021-30762

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30762
+1 in the same advisory: …30761
Use-After-Free in Apple iOS WebKit Enables RCE via Crafted Web Content

CVE-2021-30762 is a use-after-free memory-management flaw (CWE-416) in the WebKit browser engine used by Apple iOS. It is triggered when a vulnerable iPhone or iPad processes maliciously crafted web content, for example when a user browses to an attacker-controlled webpage. Successful exploitation allows arbitrary code execution with the privileges of the affected process, and the flaw scores 8.8 (high) on CVSS 3.1 (network vector, no privileges, user interaction required). Affected users are those running iOS versions that predate the fix, which Apple delivered in iOS 12.5.4 — an update targeting older devices still on the iOS 12 line. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, and EPSS assigns an 11.0% probability of exploitation within 30 days (96th percentile), though no public proof-of-concept is known.

Do: Update affected iPhones and iPads to iOS 12.5.4 or later, and users on newer iOS release lines should install the corresponding current Apple update, since the defect is in the shared WebKit component; verify the installed version via Settings > General > Software Update. Because exploitation occurs through web content and the flaw is on the CISA KEV list, patch promptly and avoid clicking links from untrusted sources until devices are updated.

8.811% KEV
  • Apple iPhone OS (iOS) iOS versions prior to 12.5.4 (fix delivered in iOS 12.5.4)
masshundreds of millions of iOS devices (WebKit runs in every iPhone; the iOS 12.5.4 fix targets the legacy-device population still on iOS 12 within Apple's 1B+…
Full article268 words · extracted from helpnetsecurity.com · click to collapse

Apple has released a security update for older iDevices (iPhones, iPads and iPods) to fix three vulnerabilities, two of which are zero-days that are apparently actively exploited in attacks in the wild.

vulnerabilities older iDevices

About the fixed flaws

The security update is iOS 12.5.4, which can still be run on older iDevices: iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation).

The two vulnerabilities Apple says “may have been actively exploited” are:

  • CVE-2021-30761, a memory corruption issue, and
  • CVE-2021-30762, a use after free bug

Both affect the WebKit browser engine (used by Safari and other iOS web browsers), both may be triggered by maliciously crafted web content and may result in remote code execution, and both have been reported by an anonymous researcher (though Apple does not say whether it’s the same individual).

The third vulnerability patched with this update is a memory corruption issue in the ASN.1 decoder that may also lead to arbitrary code execution if a maliciously crafted certificate is processed.

The last in a line of actively exploited WebKit vulnerabilities

As per usual, Apple “doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available,” and chose not share more details about these bugs.

iOS 12 is used by a minority of iDevice users – between 10 and 7%, depending on different sources – and they’ve been repeatedly asked to implement security updates in the last six months, to fix a slew of actively exploited WebKit flaws.

Users should implement the offered update as soon as possible.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/06/16/vulnerabilities-affecting-older-idevices/