ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino1

Operation Triangulation iOS Attack Details Revealed

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-32435
+1 in the same advisory: …32434
Memory Corruption in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-32435 is an out-of-bounds write (CWE-787) memory corruption flaw in the WebKit engine shipped with Apple Safari, iOS, iPadOS, and macOS. It is triggered when WebKit processes maliciously crafted web content, such as a hostile webpage or embedded HTML, and successful exploitation leads to arbitrary code execution. Because WebKit is also used by non-Apple HTML parsers and applications, the impact extends beyond Safari and Apple's own browsers. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-06-23, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. EPSS estimates a 22.8% probability of exploitation in the next 30 days (98th percentile), and a CVSS score is not yet published.

Do: Update Safari to 16.5 or later, iOS/iPadOS to 16.5 (or 15.7.6 on the legacy branch) or later, and macOS to the patched Ventura/Monterey/Big Sur releases (13.4 / 12.6.6 / 11.7.7) or later, then verify managed fleets are on fixed builds per the CISA KEV required action. Prioritize internet-exposed and high-risk users, since the flaw is confirmed exploited in the wild. If you ship or operate non-Apple products that embed WebKit, pull the fixed WebKit from the upstream project or your vendor.

8.8
group max
23% KEV
  • Apple Safari Versions prior to the WebKit fix shipped in Safari 16.5 (May 2023; see Apple advisory for exact ranges)
  • Apple iOS Versions prior to iOS 16.5 and the iOS 15.7.6 legacy-branch update
  • Apple iPadOS Versions prior to iPadOS 16.5 and the iPadOS 15.7.6 legacy-branch update
  • +2 more
mass>1,000,000,000 devices/users (WebKit is the system HTML engine on every iPhone and iPad and powers Safari on macOS)
CVE-2023-38606
Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS

CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected.

Do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines.

5.53% KEV
  • apple iPhone OS (iOS) iOS versions prior to iOS 15.7.8 and iOS 16 versions prior to iOS 16.6 (fixed in iOS 15.7.8 and iOS 16.6)
  • apple iPadOS iPadOS versions prior to 15.7.8 and iPadOS 16 versions prior to 16.6 (fixed in iPadOS 15.7.8 and iPadOS 16.6)
  • apple macOS Big Sur versions prior to 11.7.9 (fixed in macOS Big Sur 11.7.9)
  • +4 more
mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023)
CVE-2023-41990
Font Parsing Code Execution Flaw in Apple iOS, iPadOS, macOS, tvOS, watchOS

CVE-2023-41990 is a vulnerability in Apple's font processing, addressed via improved handling of caches, in which processing a maliciously crafted font file can lead to arbitrary code execution on the device. It is triggered when an application on the device processes an attacker-supplied font, and the CVSS local/user-interaction vector indicates the target user must be involved (e.g., viewing content that includes the malicious font). A successful exploit gives the attacker arbitrary code execution with high impact on confidentiality, integrity, and availability, and it was used as a component of the sophisticated multi-zero-day Operation Triangulation iPhone attack chain described in recent research. All users of Apple iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions older than the listed fixed releases are affected; Apple stated the issue was actively exploited against versions of iOS released before iOS 15.7.1. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-01-08 (EPSS ~1.3%), and no public proof-of-concept is required given the documented active use.

Do: Upgrade affected devices to iOS/iPadOS 16.3 (or iOS/iPadOS 15.7.8 for devices remaining on the 15.x line), macOS Ventura 13.2, macOS Monterey 12.6.8, or macOS Big Sur 11.7.9, plus tvOS 16.3 and watchOS 9.3; this is mandatory for U.S. federal agencies per the 2024-01-08 CISA KEV listing. Given the bug's role in the Operation Triangulation campaign, prioritize Apple fleet-wide patching and hunt for indicators of compromise from that campaign on devices that had been running pre-patch versions.

7.81% KEV
  • Apple iOS (iPhone OS) All versions prior to 16.3; iOS 15.x prior to 15.7.8 (actively exploited against versions before iOS 15.7.1)
  • Apple iPadOS All versions prior to 16.3; 15.x prior to 15.7.8
  • Apple macOS Ventura Prior to 13.2
  • +4 more
masson the order of 1 billion+ Apple devices (Apple has publicly reported over 2 billion active devices across these product lines)
Full article360 words · extracted from infosecurity-magazine.com · click to collapse

In an update to previous reports, Kaspersky’s Global Research and Analysis Team (GReAT) has disclosed new insights into the notorious Operation Triangulation at the recent Security Analyst Summit. 

The investigation delves into the complex cyber assault that targeted both the public and Kaspersky’s own employees, offering fresh details on the attack chain and its implications for iOS security.

The novel analysis revealed that the attack exploited five vulnerabilities, four of which were previously unknown zero-day flaws. 

Kaspersky experts have pinpointed an initial point of entry, which was traced back to a vulnerability in a font processing library. The second point of vulnerability was a reportedly easily exploitable flaw in the memory mapping code, providing unauthorized access to the device’s physical memory. 

Furthermore, the attackers leveraged two additional vulnerabilities to circumvent the latest hardware security measures of Apple processors. 

In their investigation, Kaspersky also noted that, apart from the ability to infect Apple devices remotely through iMessage without any user interaction, the attackers had the means to carry out attacks via the Safari web browser. Consequently, this led to the identification of a fifth vulnerability.

“The hardware-based security features of devices with newer Apple chips significantly bolster their resilience against cyber-attacks. But they are not invulnerable,” explained Boris Larin, principal security researcher at Kaspersky’s GReAT.

“Operation Triangulation is a reminder to exercise caution when handling iMessage attachments from unfamiliar sources.”

Read more on Operation Triangulation: Apple Addresses Exploited Security Flaws in iOS, macOS and Safari

Apple has officially released security updates to address these four zero-day vulnerabilities (CVE-2023-32434, CVE-2023-32435, CVE-2023-38606, CVE-2023-41990), which affect a wide range of Apple products, including iPhones, iPods, iPads, macOS devices, Apple TV and Apple Watch.

“Drawing insights from the strategies employed in Operation Triangulation offers valuable guidance. Additionally, finding a balance between system closedness and accessibility may contribute to an enhanced security posture,” Larin concluded.

Kaspersky’s experts recommended a multi-layered security approach to defend against similar threats. They urged users to regularly update their systems, exercise caution with unsolicited messages and provide their security teams with access to threat intelligence. The company intends to provide more technical details about Operation Triangulation in the near future.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/operation-triangulation-ios-details/