iPhones and Macs get patches for two vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-42824 | Kernel Privilege Escalation in Apple iOS and iPadOS (Actively Exploited) CVE-2023-42824 is a privilege escalation vulnerability in the kernel of Apple's iOS and iPadOS, addressed with improved checks in iOS 16.7.1 and iPadOS 16.7.1. It is triggered locally: an attacker who can already run code on the device (for example via a malicious app or as one stage of a chained attack) exploits the flaw to elevate privileges. Successful exploitation grants kernel-level privilege, with high confidentiality, integrity, and availability impact, meaning near-full control of the affected device. Any iPhone or iPad running iOS/iPadOS versions prior to 16.7.1 is affected, and Apple reported the issue was being actively exploited against iOS versions before 16.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-05 with no public PoC listed, making patching urgent. Do: Update affected iPhones and iPads to iOS 16.7.1 / iPadOS 16.7.1 or later (any subsequent iOS release includes the fix), and verify device versions via Settings > General > Software Update. There is no indicated workaround, so prioritize patching for high-risk users (executives, admins, journalists), since local kernel elevation bugs of this kind are commonly chained with remote code execution or sandbox-escape exploits. Per CISA's required action, apply the vendor updates promptly or restrict use of unpatched devices. | 7.8 | <1% | KEV |
| masshundreds of millions of consumer devices (Apple's active iPhone/iPad installed base exceeds 1 billion) | |
| CVE-2023-42917 +1 in the same advisory: …42916 | WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile). Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users. | 8.8 group max | 9% | KEV |
| masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base) |
Full article293 words · extracted from therecord.media · click to collapse
Apple warned customers of the latest zero-day vulnerabilities affecting several of its products, releasing an emergency security update on Thursday. The vulnerabilities — CVE-2023-42916 and CVE-2023-42917 — were discovered by Clément Lecigne of Google's Threat Analysis Group and affect iPhone XS and later; several models of iPads; and Macs running macOS Monterey, Ventura or Sonoma. “Processing web content may disclose sensitive information,” the company said in all three advisories. “Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.” The Cybersecurity and Infrastructure Security Agency (CISA) released its own warning about the vulnerabilities, urging customers of the company to apply the patches available. Read more: Latest severe Chrome bug prompts CISA warning Michael Covington, a vice president at Apple device security and management company Jamf, told Recorded Future News that the bugs revolve around Apple’s WebKit. The exploits involving the vulnerabilities, according to Covington, show that attackers continue to focus on finding flaws in the framework that downloads and presents web-based content. “The latest bugs could lead to both data leakage and arbitrary code execution, and appear to be tied to targeted attacks that are common against high-risk users,” he said. “Though these patches validate that Apple devices are not immune to cyber threats, the patching process is helping to reduce the attack surface. Now that the patches are issued, it is up to users, and organizations that utilize Apple devices for work, to update their devices and monitor for compliance to ensure that all critical devices are no longer vulnerable as soon as possible.” Apple previously warned in October about hackers exploiting CVE-2023-42824 – a vulnerability affecting iPhone XS and later as well as several versions of the iPad Pro and Air.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/iphones-macs-vulnerabilities-apple-webkit