Latest iOS 12.1.4 Update Patches 2 Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-6223 | Apple iOS/macOS Group FaceTime Auto-Answer Flaw Enables Silent Eavesdropping A logic flaw in the handling of Group FaceTime calls on Apple iOS and macOS let the initiator of a Group FaceTime call cause the recipient's device to answer automatically, without the user accepting. An attacker who called a victim's FaceTime identity could thereby listen in on the recipient's surroundings before the call was accepted - a silent eavesdropping condition consistent with the CVSS confidentiality-high rating. Users of iPhones and iPads running iOS releases with Group FaceTime prior to 12.1.4, and Macs running macOS Mojave prior to the 10.14.3 Supplemental Update, were affected. Apple shipped fixes in iOS 12.1.4 and the macOS Mojave 10.14.3 Supplemental Update. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation, while EPSS puts near-term exploitation probability at about 2.6% (85th percentile) and no public proof-of-concept code is known. Do: Upgrade iPhones and iPads to iOS 12.1.4 or later and Macs to macOS Mojave 10.14.3 Supplemental Update or later. As an interim mitigation, disable FaceTime or avoid placing/accepting Group FaceTime calls until patched, and verify managed fleets have the updates applied per the CISA KEV required action. | 7.5 | 3% | KEV |
| masshundreds of millions of consumer devices (Apple's active iPhone/Mac install base, with the affected Group FaceTime-era iOS and macOS Mojave releases widely… | |
| CVE-2019-7286 | Out-of-Bounds Write Local Privilege Escalation in Apple iOS and macOS CVE-2019-7286 is a memory corruption flaw (an out-of-bounds write, CWE-787) in Apple's iOS and macOS that Apple addressed with improved input validation. It is triggered locally: the CVSS vector shows a local attack vector requiring user interaction, and an application that corrupts memory through the flaw may gain elevated privileges with high impact on confidentiality, integrity, and availability. Users running iPhones or iPads on iOS before 12.1.4, or macOS Mojave systems without the 10.14.3 Supplemental Update, are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), which indicates confirmed exploitation in the wild, and EPSS assigns it a 15.6% probability of exploitation within 30 days (97th percentile). No public proof-of-concept is catalogued, but defenders should treat it as actively exploited. Do: Update all iPhones and iPads to iOS 12.1.4 or later and apply the macOS Mojave 10.14.3 Supplemental Update (or a later macOS release) on Macs, per the CISA KEV required action. Inventory for devices that cannot run the fixed versions, restrict untrusted applications on them or retire them, since the flaw allows local apps to gain elevated privileges. Given the KEV listing, treat this as an actively exploited vulnerability and prioritize patching in any KEV-driven remediation program. | 7.8 | 16% | KEV |
| masshundreds of millions of Apple devices affected at the time of disclosure; current count of unpatched legacy devices unknown | |
| CVE-2019-7287 | Out-of-Bounds Write in Apple iOS Allows Kernel-Privilege Code Execution Apple iOS versions prior to 12.1.4 contain a memory corruption flaw — an out-of-bounds write (CWE-787) — which Apple fixed with improved input validation in iOS 12.1.4. Based on the flaw's CVSS scoring (local attack vector, user interaction required), it is triggered when a user opens or runs a malicious application on the device. A successful exploit lets that application execute arbitrary code with kernel privileges, giving the attacker full device control and access to all data on the phone. All Apple iPhones (iPhone OS) running iOS versions before 12.1.4 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), confirming known in-the-wild exploitation; EPSS currently assigns a 4.6% probability of exploitation activity within 30 days (91st percentile), no public proof-of-concept is cataloged, and ransomware use is unknown. Do: Apply Apple's update without delay, per CISA KEV's required action: update all iPhones and iOS devices to iOS 12.1.4 or later. Inventory your fleet for devices still running iOS 12.1.3 or earlier and prioritize patching them; on unpatched legacy devices, avoid opening untrusted applications until updated. Where hardware allows, move older devices off iOS 12 to a currently supported iOS release. | 7.8 | 5% | KEV |
| mass≈hundreds of millions of iPhone devices at time of disclosure (early 2019) | |
| CVE-2019-7288 | The issue was addressed with improved validation on the FaceTime server. The issue was addressed with improved validation on the FaceTime server. This issue is fixed in macOS Mojave 10.14.3 Supplemental Update, iOS 12.1.4. A thorough security audit of the FaceTime service uncovered an issue with Live Photos . NVD description · AI analysis pending | 9.8 | 1% |
| — |
Full article447 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalFeb 08, 2019
Apple has finally released iOS 12.1.4 software update to patch the terrible Group FaceTime privacy bug that could have allowed an Apple user to call you via the FaceTime video chat service and hear or see you before you even pick up the call without your knowledge.
The Facetime bug (CVE-2019-6223) was discovered by 14-year-old Grant Thompson of Catalina Foothills High School while he was trying to set up a Group FaceTime session with his friends.
Thompson reported the bug to the company a week before it made headlines across the internet, forcing Apple to temporarily disable the group calling feature within FaceTime.
In its advisory published Thursday, Apple described the bug as "a logic issue existed in the handling of Group FaceTime calls," that also impacted the group FaceTime calling feature on Apple's macOS Mojave 10.14.2.
Along with Thompson, Apple has also credited Daven Morris of Arlington, Texas, in its official advisory for reporting this bug.
According to media reports, Apple has confirmed to "compensate" the family and help towards the teenager's future education costs as part of its Bug Bounty program, though it is unclear how much the company is going to pay.
Two More In-The-Wild Zero-Day Flaws Discovered
The iOS 12.1.4 update also patches three more security vulnerabilities, two of which were also reportedly being exploited in the wild, confirmed by Google Project Zero researchers, who discovered and reported these vulnerabilities to Apple. The last bug was also related to FaceTime.
- CVE-2019-7286: a memory corruption issue that could allow a malicious application to gain elevated privileges on the vulnerable Apple device.
- CVE-2019-7287: a memory corruption issue that could allow a malicious application to execute arbitrary code with kernel privileges.
- CVE-2019-7288: discovered by the Apple security team, this flaw is another FaceTime issue with Live Photos.
If you haven't yet, you are highly recommended to update your Apple devices with iOS 12.1.4 release, which is available for the iPhone 5S, and later, iPad Air and later, and iPod touch 6th generation.
To run the update on your iPhone, iPad or iPod, just go to Settings→ General → Software Update and click the 'Download and Install' button.
If you are a Mac owner, you should also install the new macOS Mojave 10.14.3 update on your computer that also fixes three of the four vulnerabilities briefed above, including the FaceTime issues.
To update your Mac computer, just go to Apple menu in the top left corner of your computer, select 'System Preferences,' click 'Software Update' and download the new update.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/02/ios-security-update-facetime.html