ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23529
WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari

CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known.

Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched.

8.810% KEV
  • Apple iPhone OS (iOS) iOS versions prior to the fixed releases; fixed in iOS 16.3.1 and in iOS 15.7.4 on the legacy branch
  • Apple iPadOS iPadOS versions prior to the fixed releases; fixed in iPadOS 16.3.1 and in iPadOS 15.7.4 on the legacy branch
  • Apple macOS (Ventura) macOS Ventura versions prior to 13.2.1
  • +1 more
massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran…
CVE-2023-32439
Type Confusion in Apple WebKit (Safari, iOS, iPadOS, macOS) Enables Code Execution

Apple's WebKit engine, used by Safari and shipped with iOS, iPadOS, and macOS, contains a type confusion vulnerability (CWE-843) that leads to code execution when processing maliciously crafted web content. An attacker can trigger the flaw by inducing a victim to load attacker-controlled web content, for example by visiting a crafted webpage or opening malicious HTML in any application that renders it with WebKit. Successful exploitation grants the attacker arbitrary code execution within the web-content processing context of the affected browser or application. The exposure is broad: every iPhone, iPad, and Mac running vulnerable WebKit builds is affected, and the flaw could also impact HTML parsers in non-Apple products that rely on WebKit. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-06-23, confirming known in-the-wild exploitation (ransomware use unknown); no public proof-of-concept is known, and CISA's required action is to apply updates per vendor instructions.

Do: Apply Apple's security updates for iOS, iPadOS, macOS, and Safari immediately, following vendor instructions as required by the CISA KEV catalog, since the flaw is confirmed exploited in the wild. Administrators should also inventory any non-Apple applications, HTML parsers, or embedded browsers that use WebKit and apply the corresponding vendor patches when available. Until patching is complete, treat unsolicited web links and HTML content as a primary attack vector and prioritize updates on internet-facing and user-facing Apple systems.

8.8
group max
24% KEV
  • Apple Safari (WebKit)
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • +2 more
masshundreds of millions to over a billion users (WebKit ships with every iPhone, iPad, and Mac)
CVE-2023-28205
Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile).

Do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content.

8.827% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +3 more
mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari)
CVE-2023-28206
Out-of-Bounds Write in Apple IOSurfaceAccelerator Allows Kernel-Level Code Execution

Apple's IOSurfaceAccelerator component in iOS, iPadOS, and macOS contains an out-of-bounds write flaw (CWE-787). The bug is triggered by an application running locally on the device, which can corrupt memory in the component during a write past a buffer boundary. A successful exploit allows the app to execute arbitrary code with kernel privileges, giving it full control of the device beyond the normal app sandbox. Any user of an Apple iOS, iPadOS, or macOS device running an affected, unpatched version is exposed. The flaw was added to CISA KEV on 2023-04-10, confirming known in-the-wild exploitation; ransomware use is unknown, no public PoC is available, and EPSS assigns a 24.5% probability of exploitation within 30 days (98th percentile).

Do: Update all iPhones, iPads, and Macs to the latest iOS/iPadOS/macOS versions available as of April 2023, per CISA's required action and Apple's security advisories. Use MDM or patch-reporting tooling to inventory endpoints and confirm no devices remain on pre-patch builds. Because exploitation is confirmed in the wild and any local app can act as the trigger, patching is the primary mitigation and there is no dependable configuration workaround.

8.623% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's active iPhone/iPad/Mac installed base exceeds 1 billion)
CVE-2023-37450
+1 in the same advisory: …38606
Arbitrary Code Execution in Apple WebKit (iOS, iPadOS, macOS, Safari, tvOS, watchOS)

CVE-2023-37450 is a high-severity (CVSS 8.8) arbitrary code execution vulnerability in Apple's WebKit browser engine, affecting iOS, iPadOS, Safari, macOS Ventura, tvOS, watchOS, and WebKitGTK. It is triggered when an affected device processes maliciously crafted web content — for example, when a user is lured into visiting an attacker-controlled webpage (user interaction is required, hence the UI:R CVSS vector). Successful exploitation grants the attacker arbitrary code execution within the web-content/browser context, the typical entry point for full iPhone, iPad, or Mac compromise chains. Anyone running iPhone OS/iPadOS earlier than 16.6, Safari earlier than 16.5.2, macOS Ventura earlier than 13.5, tvOS earlier than 16.6, watchOS earlier than 9.6, or unpatched WebKitGTK builds is affected. Apple reports the issue may have been actively exploited before it was patched, CISA added it to the KEV catalog on 2023-07-13, and EPSS assigns an 18.9% probability (97th percentile) of exploitation over the next 30 days.

Do: Upgrade immediately to iOS 16.6 / iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6, and watchOS 9.6, or apply the latest available patch for older OS branches on devices that cannot take the 16.x/Ventura updates; this is a CISA KEV entry with a federal remediation requirement. Because exploitation occurs through normal web browsing, patching is the only reliable mitigation — avoid untrusted websites as an interim measure. WebKitGTK users should update to the latest patched WebKitGTK release and verify that dependent applications have been rebuilt against the fixed library.

8.8
group max
19% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 16.6
  • Apple iPadOS All versions prior to iPadOS 16.6
  • Apple Safari All versions prior to Safari 16.5.2
  • +4 more
mass≈2 billion active Apple devices (WebKit is the web engine for iOS/iPadOS, Safari, tvOS and watchOS); no public counts of exploited devices are known
CVE-2023-41061
Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS

Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11.

Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds.

7.84% KEV
  • Apple iPhone OS (iOS) all versions prior to 16.6.1
  • Apple iPadOS all versions prior to 16.6.1
  • Apple watchOS all versions prior to 9.6.2
massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched)
CVE-2023-41064
ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution

CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs.

Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices.

7.845% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion)
Full article257 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 07, 2023

Apple rolled out emergency security updates to address two new actively exploited zero-day vulnerabilities impacting iPhones and Macs.

The two Apple zero-day vulnerabilities, tracked as CVE-2023-41064 and CVE-2023-41061, reside in the Image I/O and Wallet frameworks.

CVE-2023-41064 is a buffer overflow issue that was reported by researchers from researchers at Citizen Lab. The IT giant addressed the flaw with improved memory handling.

“Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.” reads the advisory.

CVE-2023-41061 is a validation issue that was discovered by Apple. The IT giant addressed the flaw with improved logic. An attacker can achieve arbitrary code execution by tricking the device into processing a specially crafted attachment.

“A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.” reads the advisory.

Apple addressed the flaws with the release of macOS Ventura 13.5.2, iOS 16.6.1, iPadOS 16.6.1, and watchOS 9.6.2.

The company has already patched 13 actively exploited zero-day vulnerabilities in 2023, below is the list of the flaws fixed by the company:

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150485/hacking/apple-discloses-2-new-actively-exploited-zero-day-flaws-in-iphones-macs.html