Apple discloses zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41061 | Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11. Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds. | 7.8 | 4% | KEV |
| massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched) | |
| CVE-2023-41064 | ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs. Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices. | 7.8 | 45% | KEV |
| masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion) |
Full article540 words · extracted from therecord.media · click to collapse
Editor's note, 4:15 p.m. ET: This story has been updated with information from Citizen Lab. Apple released software updates on Thursday to address two zero-day vulnerabilities that researchers said were used to deliver NSO Group’s Pegasus spyware to at least one victim. Cybersecurity researchers at the Citizen Lab at The University of Toronto said that all users of Apple devices should update their operating systems immediately to fix the bugs. "Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with international offices, Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware," the researchers said. "The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim," the researchers said. One bug, tracked as CVE-2023-41064, allowed devices — including some iPhones, iPads, Macs, and Apple Watches — to become vulnerable to attack when processing “a maliciously crafted image,” Apple said. It affects the Image I/O framework, specifically. The other vulnerability, CVE-2023-41061, similarly creates security issues if a device is sent a “maliciously crafted attachment.” That bug arose in the company’s Wallet function. In both cases, Apple said it was “aware of a report that this issue may have been actively exploited.” Apple declined to comment more about the bugs. Citizen Lab said it had "immediately disclosed our findings to Apple and assisted in their investigation." The software updates apply to macOS Ventura, iOS, iPadOS and watchOS. The patches were made available as part of regular updates to those products. They were not labeled as a Rapid Security Response — the term Apple uses for bug fixes issued urgently between full OS updates. With the disclosure of those two vulnerabilities, the company has now patched 13 zero-days in 2023. Since it was first developed in 2011, Pegasus has been used across the globe, often by governments spying on their citizens. It has been deployed to target assassinated Saudi journalist Jamal Khashoggi, members of the Catalan independence movement and human rights investigators in Mexico. In recent years, regulators have attempted to prevent its spread, with the European Parliament urging EU member nations to ban it. U.S. President Joe Biden signed an executive order earlier this year blocking the use of commercial spyware by the government. It's not the first time this year Apple has disclosed zero-days reportedly used in spyware campaigns: Two bugs fixed in June were exploited in a campaign that the Russian government blamed on the U.S. A separate Rapid Security Response in July required a redo by Apple after the first version of the patch prevented some websites from displaying properly.
No previous article
No new articles
Joe Warminsky
has been the news editor for Recorded Future News since 2022. He has three decades of experience as an editor and writer in the Washington, D.C., area. He previously he helped lead CyberScoop for more than five years. Prior to that, he was a digital editor at WAMU 88.5, the NPR affiliate in Washington, and he spent more than a decade editing coverage of Congress for CQ Roll Call.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-discloses-two-zero-days-in-new-updates