ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple Releases Updates to Address Zero-Day Flaws in iOS, iPadOS, macOS, and Safari

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-28205CVE-2023-28206CVE-2023-23529

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23529
WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari

CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known.

Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched.

8.810% KEV
  • Apple iPhone OS (iOS) iOS versions prior to the fixed releases; fixed in iOS 16.3.1 and in iOS 15.7.4 on the legacy branch
  • Apple iPadOS iPadOS versions prior to the fixed releases; fixed in iPadOS 16.3.1 and in iPadOS 15.7.4 on the legacy branch
  • Apple macOS (Ventura) macOS Ventura versions prior to 13.2.1
  • +1 more
massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran…
CVE-2023-28205
Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile).

Do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content.

8.827% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +3 more
mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari)
CVE-2023-28206
Out-of-Bounds Write in Apple IOSurfaceAccelerator Allows Kernel-Level Code Execution

Apple's IOSurfaceAccelerator component in iOS, iPadOS, and macOS contains an out-of-bounds write flaw (CWE-787). The bug is triggered by an application running locally on the device, which can corrupt memory in the component during a write past a buffer boundary. A successful exploit allows the app to execute arbitrary code with kernel privileges, giving it full control of the device beyond the normal app sandbox. Any user of an Apple iOS, iPadOS, or macOS device running an affected, unpatched version is exposed. The flaw was added to CISA KEV on 2023-04-10, confirming known in-the-wild exploitation; ransomware use is unknown, no public PoC is available, and EPSS assigns a 24.5% probability of exploitation within 30 days (98th percentile).

Do: Update all iPhones, iPads, and Macs to the latest iOS/iPadOS/macOS versions available as of April 2023, per CISA's required action and Apple's security advisories. Use MDM or patch-reporting tooling to inventory endpoints and confirm no devices remain on pre-patch builds. Because exploitation is confirmed in the wild and any local app can act as the trigger, patching is the primary mitigation and there is no dependable configuration workaround.

8.623% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's active iPhone/iPad/Mac installed base exceeds 1 billion)
Full article381 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 08, 2023Zero-Day / Endpoint Security

Apple on Friday released security updates for iOS, iPadOS, macOS, and Safari web browser to address a pair of zero-day flaws that are being exploited in the wild.

The two vulnerabilities are as follows -

  • CVE-2023-28205 - A use after free issue in WebKit that could lead to arbitrary code execution when processing specially crafted web content.
  • CVE-2023-28206 - An out-of-bounds write issue in IOSurfaceAccelerator that could enable an app to execute arbitrary code with kernel privileges.

Apple said it addressed CVE-2023-28205 with improved memory management and the second with better input validation, adding it's aware the bugs "may have been actively exploited."

Credited with discovering and reporting the flaws are Clément Lecigne of Google's Threat Analysis Group (TAG) and Donncha Ó Cearbhaill of Amnesty International's Security Lab.

Details about the two vulnerabilities have been withheld in light of active exploitation and to prevent more threat actors from abusing them.

The updates are available in version iOS 16.4.1, iPadOS 16.4.1, macOS Ventura 13.3.1, and Safari 16.4.1. The fixes also span a wide range of devices -

  • iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
  • Macs running macOS Big Sur, Monterey, and Ventura

Apple has patched three zero-days since the start of the year. In February, Apple addressed another actively exploited zero-day (CVE-2023-23529) in WebKit that could result in arbitrary code execution.

The development also comes as Google TAG disclosed that commercial spyware vendors are leveraging zero-days in Android and iOS to infect mobile devices with surveillance malware.

Apple Expands Patches to Older Devices

Apple, on April 10, 2023, backported patches for the two actively exploited flaws to include older iPhones, iPads, and Macs. The updates are available for the following devices -

  • iOS 15.7.5 and iPadOS 15.7.5 - iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
  • macOS Big Sur 11.7.6 and Monterey 12.6.5 (It's worth noting that the update only addresses CVE-2023-28206.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/04/apple-releases-updates-to-address-zero.html