ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Apple‌ Issues Patches to Combat Ongoing 0

criticalVulnerability exploited in the wildimportance 60CVE-2021-30713CVE-2021-30663CVE-2021-30665

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-30665
+1 in the same advisory: …30663
Memory Corruption in Apple WebKit Enables RCE on iOS, macOS, tvOS, watchOS

CVE-2021-30665 is a memory corruption flaw (CWE-787, out-of-bounds write) in the WebKit engine shared across Apple's operating systems, fixed through improved state management. It is triggered when a device processes maliciously crafted web content, for example when a user loads an attacker-controlled web page or other web-rendered content, which is reflected in the required user-interaction element of the CVSS vector. Successful exploitation may lead to arbitrary code execution on the device. Essentially all Apple devices running versions of iOS, iPadOS, macOS Big Sur, tvOS, or watchOS earlier than the patched releases were affected, spanning the bulk of Apple's active installed base at the time. Apple reported the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; EPSS assigns a 3.7% probability of exploitation in the next 30 days (89th percentile).

Do: Upgrade iPhones and iPads to iOS/iPadOS 14.5.1 (or iOS 12.5.3 on devices that cannot run 14.x), Macs to macOS Big Sur 11.3.1, Apple TVs to tvOS 14.6, and Apple Watches to watchOS 7.4.1. Because exploitation occurs through crafted web content, patching is the only reliable mitigation; use MDM or device inventory to confirm no managed Apple devices remain on pre-fix OS versions and treat any stragglers as actively at risk.

8.84% KEV
  • apple iOS (iPhone OS) all versions prior to 14.5.1; iOS 12.x prior to 12.5.3 (fixed in iOS 14.5.1 and iOS 12.5.3)
  • apple iPadOS all versions prior to 14.5.1 (fixed in iPadOS 14.5.1)
  • apple macOS (Big Sur) macOS Big Sur versions prior to 11.3.1 (fixed in Big Sur 11.3.1)
  • +2 more
mass>1 billion active Apple devices (iOS/iPadOS/macOS/tvOS/watchOS installed base)
CVE-2021-30713
Privacy Preferences (TCC) Bypass in Apple macOS, Actively Exploited

CVE-2021-30713 is a permissions/authorization flaw (CWE-862) in Apple macOS that allows a malicious application already running on a machine to bypass the user's Privacy preferences, which govern which apps may access protected user data such as files, camera, microphone, and other consent-protected resources. The flaw is triggered locally: a malicious app that a user has launched can silently circumvent the Privacy controls without the usual approval prompt. Successful exploitation grants the attacker access to user data that should have required explicit user consent, with high impact to confidentiality, integrity, and availability per its 7.8 CVSS score. Any Mac running a version of macOS prior to the macOS Big Sur 11.4 fix is affected. Apple acknowledged a report that the issue was being actively exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03; the EPSS score of 7.0% (94th percentile) further indicates meaningful near-term exploitation risk.

Do: Upgrade affected Macs to macOS Big Sur 11.4 or later immediately, as this issue is listed in CISA's KEV catalog with active exploitation confirmed. Audit Macs for unknown or recently installed applications that accessed protected data (files, camera, microphone) without a consent prompt, and prioritize internet-facing and high-value endpoints. Since Apple shipped this fix alongside other actively exploited zero-days in the same release cycle, ensure devices are fully updated rather than partially patched.

7.87% KEV
  • Apple macOS (Big Sur) prior to 11.4
  • Apple macOS / Mac OS X (per CISA CPE)
masstens of millions of Macs (macOS runs on an installed base estimated at 100M+ devices, and Big Sur was the current release when the patch shipped)
Full article524 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 25, 2021

Apple on Monday rolled out security updates for iOS, macOS, tvOS, watchOS, and Safari web browser to fix multiple vulnerabilities, including an actively exploited zero-day flaw in macOS Big Sur and expand patches for two previously disclosed zero-day flaws.

Tracked as CVE-2021-30713, the zero-day concerns a permissions issue in Apple's Transparency, Consent, and Control (TCC) framework in macOS that maintains a database of each user's consents. The iPhone maker acknowledged that the issue may have been exploited in the wild but stopped short of sharing specifics.

The company noted that it rectified the problem with improved validation.

However, in a separate report, mobile device management company Jamf said the bypass flaw was being actively exploited by XCSSET, a malware that's been out in the wild since August 2020 and known to propagate via modified Xcode IDE projects hosted on GitHub repositories and plant malicious packages into legitimate apps installed on the target system.

"The exploit in question could allow an attacker to gain Full Disk Access, Screen Recording, or other permissions without requiring the user's explicit consent — which is the default behavior," Jamf researchers Stuart Ashenbrenner, Jaron Bradley, and Ferdous Saljooki said in a write-up.

Taking the form of a AppleScript module, the zero-day flaw allowed the hackers to exploit the devices XCSSET was installed to leverage the permissions that have already been provided to the trojanized application to amass and exfiltrate sensitive information.

Specifically, the malware checked for screen capture permissions from a list of installed applications, such as Zoom, Discord, WhatsApp, Slack, TeamViewer, Upwork, Skype, and Parallels Desktop, to inject the malware ("avatarde.app") into the app's folder, thereby inheriting the necessary permissions required to carry out its nefarious tasks.

"By leveraging an installed application with the proper permissions set, the attacker can piggyback off that donor app when creating a malicious app to execute on victim devices, without prompting for user approval," the researchers noted.

XCSSET was also the subject of closer scrutiny last month after a new variant of the malware was detected targeting Macs running on Apple's new M1 chips to steal wallet information from cryptocurrency apps. One of its primary functions is to siphon Safari browser cookies as well as install a developer version of the Safari application to load JavaScript backdoors from its command-and-control server.

Also fixed as part of Monday's updates are two other actively exploited flaws in its WebKit browser engine affecting Safari, Apple TV 4K, and Apple TV HD devices, almost three weeks after Apple addressed the same issues in iOS, macOS, and watchOS earlier this month.

  • CVE-2021-30663 - An integer overflow issue in WebKit, which could be exploited to achieve arbitrary code execution when processing maliciously crafted web content.
  • CVE-2021-30665 - A memory corruption issue in WebKit that could lead to arbitrary code execution when processing maliciously crafted web content.

Users of Apple devices are recommended to update to the latest versions to mitigate the risk associated with the flaws.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/05/apple-issues-patches-to-combat-ongoing.html