ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple iOS and macOS Flaw Could've Let Apps Eavesdrop on Your Conversations with Siri

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-32946CVE-2022-42827

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-32946
This issue was addressed with improved entitlements.

This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.

NVD description · AI analysis pending
5.5<1%
  • apple ipados
  • apple iphone os
CVE-2022-42827
Actively Exploited Out-of-Bounds Write in Apple iOS and iPadOS Kernel

CVE-2022-42827 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS and iPadOS, caused by insufficient bounds checking and fixed with improved bounds checking. It is triggered locally by a malicious application running on a vulnerable device, consistent with the CVSS vector (local attack vector, user interaction required, no special privileges). A successful attacker can execute arbitrary code with kernel privileges, escaping the app sandbox and gaining full control of the device's operating system layer. Any iPhone or iPad running iOS/iPadOS versions below the fixed releases (iOS 15.7.1, iPadOS 15.7.1, iOS 16.1, iPadOS 16) is affected, which at the time of disclosure covered essentially the entire unpatched iOS/iPadOS fleet. Apple reported the flaw may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-25; no public proof-of-concept is known, but in-the-wild exploitation is confirmed.

Do: Update all iPhones and iPads to iOS 15.7.1 / iPadOS 15.7.1 at minimum, or preferably iOS 16.1 / iPadOS 16 or later. Because exploitation requires running a malicious app on the device, treat unpatched devices as at-risk, verify fleet OS builds via MDM or device inventory, and restrict app installs from untrusted sources until patched. The CVE is on CISA's KEV list, making patching mandatory for federal agencies and strongly recommended for all organizations.

7.81% KEV
  • Apple iPhone OS (iOS) All iOS versions prior to 15.7.1 and prior to 16.1
  • Apple iPadOS All iPadOS versions prior to 15.7.1 and prior to 16
masshundreds of millions of devices (effectively all iPhones/iPads not yet on iOS 15.7.1/iPadOS 15.7.1 or iOS 16.1/iPadOS 16 at disclosure)
Full article443 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 27, 2022

A now-patched security flaw in Apple's iOS and macOS operating systems could have potentially enabled apps with Bluetooth access to eavesdrop on conversations with Siri.

Apple said "an app may be able to record audio using a pair of connected AirPods," adding it addressed the Core Bluetooth issue in iOS 16.1 with improved entitlements.

Credited with discovering and reporting the bug in August 2022 is app developer Guilherme Rambo. The bug, dubbed SiriSpy, has been assigned the identifier CVE-2022-32946.

"Any app with access to Bluetooth could record your conversations with Siri and audio from the iOS keyboard dictation feature when using AirPods or Beats headsets," Rambo said in a write-up.

"This would happen without the app requesting microphone access permission and without the app leaving any trace that it was listening to the microphone."

The vulnerability, according to Rambo, relates to a service called DoAP that's included in AirPods for Siri and Dictation support, thereby enabling a malicious actor to craft an app that could be connected to the AirPods via Bluetooth and record the audio in the background.

This is compounded by the fact that "there's no request to access the microphone, and the indication in Control Center only lists 'Siri & Dictation,' not the app that was bypassing the microphone permission by talking directly to the AirPods over Bluetooth LE."

While the attack requires that the app has access to Bluetooth, this restriction can be trivially bypassed as users granting Bluetooth access to the app are unlikely to expect that it could also open the door to accessing their conversations with Siri and audio from dictation.

On macOS, however, the exploit could be abused to achieve a total bypass of the Transparency, Consent and Control (TCC) security framework, meaning any app can record conversations with Siri without requesting for any permissions in the first place.

Rambo said the reason for this behavior is owing to the lack of entitlement checks for BTLEServerAgent, the daemon service responsible for handling DoAP audio.

A software patch remediating this flaw is available for iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later. It has also been resolved in all supported versions of macOS.

The iOS 16.1 update, which was released on October 24, 2022, comes with fixes for a total of 20 flaws, including a Kernel vulnerability (CVE-2022-42827) that Apple disclosed as being actively exploited in the wild.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/10/apple-ios-and-macos-flaw-couldve-let.html