ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes actively exploited iOS, macOS zero-day (CVE-2022-22620)

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-22620

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-22620
WebKit Use-After-Free (CVE-2022-22620) Enables RCE on iOS, iPadOS, and macOS

CVE-2022-22620 is a use-after-free (CWE-416) in Apple's WebKit browser engine, the component that renders web content on iPhones, iPads, Macs, and Safari. An attacker triggers it by getting a victim to process maliciously crafted web content, such as visiting an attacker-controlled webpage, requiring no privileges and only user interaction with the content. Successful exploitation may lead to arbitrary code execution in the context of the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High). All devices running iOS or iPadOS before 15.3.1, macOS Monterey before 12.2.1, or Safari before 15.3 are affected, which effectively means the broad Apple user base at the time of disclosure. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-11 and carries a 16.2% EPSS probability of exploitation in the next 30 days (97th percentile).

Do: Update iPhones and iPads to iOS/iPadOS 15.3.1, Macs to macOS Monterey 12.2.1, and Safari to version 15.3 (builds 16612.4.9.1.8 or 15612.4.9.1.8), per Apple's vendor instructions. Inventory for devices still on pre-patch versions, prioritizing user workstations and mobile devices that browse web or HTML email content, since WebKit loads content automatically. Note the vulnerability is listed in CISA's KEV catalog with 'apply updates per vendor instructions' as the required action, so patching is the only reliable mitigation.

8.816% KEV
  • Apple iOS (iPhone OS) prior to iOS 15.3.1
  • Apple iPadOS prior to iPadOS 15.3.1
  • Apple macOS (Monterey) prior to macOS Monterey 12.2.1
  • +1 more
mass≈1 billion+ Apple devices (WebKit is the system web engine on every iPhone, iPad, and Mac)
Full article273 words · extracted from helpnetsecurity.com · click to collapse

Another month, another zero-day (CVE-2022-22620) exploited in the wild that has been fixed by Apple.

CVE-2022-22620

About CVE-2022-22620

CVE-2022-22620 is a use after free issue in WebKit, the browser engine used in Safari and all iOS web browsers.

Apple fixed it in iOS 15.3.1 and iPadOS 15.3.1, macOS Monterey 12.2.1, and Safari 15.3.

“Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited,” the company noted in the security update release notes, and credited an anonymous researcher with reporting it.

“WebKit vulnerabilities are typically exploited by exposing the device to a malicious webpage, but anything rendered using the WebKit engine could potentially be used to expose the vulnerability,” noted Dr. Johannes Ullrich, Dean of Research at the SANS Technology Institute.

“Currently, it isn’t clear if other devices using WebKit are vulnerable, or if the patch will be released as a Safari update for older macOS versions. But typically, Apple does not release vulnerability information until all affected operating systems are patched.”

Apply the updates

As per usual, no specific details about the vulnerability or the attacks have been shared.

Many of the actively exploited zero-day vulnerabilities in iOS fixed by Apple in the last several years turned out to be leveraged to deliver NSO Group’s Pegasus spyware to select targets in limited attacks.

Still, there is a possibility the attacks are more widespread, so users of iPhones, iPads and Macs should not rely on their devices to check for and inform them about available updates, but look for themselves and implement them as soon as possible.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/02/11/cve-2022-22620/