ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes three actively exploited iOS zero-days

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-1870CVE-2021-1871CVE-2021-1782

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1782
Race Condition Privilege Escalation in Apple iOS, macOS, watchOS, and tvOS

A race condition caused by improper locking (CWE-667) in Apple's operating systems could allow local privilege escalation. The flaw is triggered by a malicious application already running on the device that exploits a timing race; exploitation requires only low local privileges and no user interaction, though the attack complexity is rated high. A successful attacker gains elevated privileges with high impact to the confidentiality, integrity, and availability of the device. Users of iPhone, iPad, Mac, Apple Watch, and Apple TV running versions earlier than iOS/iPadOS 14.4, macOS Big Sur 11.2 (or the 2021-001 security updates for Catalina and Mojave), watchOS 7.3, and tvOS 14.4 are affected. Apple reported the issue as actively exploited in the wild, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, and no public proof-of-concept is known.

Do: Upgrade to iOS/iPadOS 14.4, watchOS 7.3, and tvOS 14.4; on Macs, upgrade to macOS Big Sur 11.2 or apply Security Update 2021-001 for Catalina and Mojave. As an interim mitigation, avoid installing untrusted applications, since exploitation requires a malicious local app. This vulnerability is in the CISA KEV catalog, so organizations subject to the required action should verify that all managed Apple devices are running the patched versions.

7.02% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 14.4
  • Apple iPadOS versions prior to iPadOS 14.4
  • Apple macOS Big Sur versions prior to macOS Big Sur 11.2
  • +4 more
masshundreds of millions of Apple devices (estimate based on Apple's active installed base exceeding 1 billion devices)
CVE-2021-1870
+1 in the same advisory: …1871
WebKit Logic Flaw Enables Remote Code Execution on iOS, iPadOS, and macOS

CVE-2021-1870 is a logic flaw in Apple's WebKit browser engine, addressed in iOS 14.4, iPadOS 14.4, macOS Big Sur 11.2, and Security Update 2021-001 for Catalina and Mojave via improved restrictions. A remote attacker can trigger the flaw through hostile web content processed by WebKit on a vulnerable device, with no authentication or privileges required per the CVSS 3.1 network-vector scoring. Successful exploitation allows arbitrary code execution on the affected device. All users of iPhone OS/iPadOS prior to 14.4 and macOS prior to the listed fixes are affected, as WebKit ships with every Apple device, and WebKitGTK/Fedora users of the same engine are also potentially impacted. Apple reported the issue may have been actively exploited in the wild as a zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03.

Do: Upgrade iPhones/iPads to iOS/iPadOS 14.4, Macs to macOS Big Sur 11.2, and apply Security Update 2021-001 on Catalina and Mojave. Fedora/WebKitGTK users should install the distribution's updated WebKitGTK packages. The issue is on the CISA KEV list with a required action of applying vendor updates; no public PoC or specific mitigation is known, so patching is the primary remediation.

9.88% KEV
  • apple iphone os (iOS) versions prior to iOS 14.4
  • apple ipados versions prior to iPadOS 14.4
  • apple macos (Big Sur) versions prior to macOS Big Sur 11.2
  • +4 more
masson the order of 1+ billion Apple devices (WebKit ships in every iPhone, iPad, and Mac)
Full article334 words · extracted from helpnetsecurity.com · click to collapse

Apple has release a new batch of security updates and has fixed three iOS zero-days that “may have been actively exploited” by attackers.

exploited iOS zero-days

The three zero-days

Two of the zero-day vulnerabilities (CVE-2021-1870 and CVE-2021-1871) are logic issues affecting the WebKit browser engine, which may allow a remote attacker to achieve code execution on devices running a vulnerable version of iOS or iPadOS (i.e., those prior to version 14.4).

The third zero-day (CVE-2021-1782) affects the operating systems’ kernel. It is a race condition that can be exploited by a malicious application to elevate privileges on a vulnerable iPhone or iPad. CVE-2021-1782 also affects watchOS and tvOS, and has been fixed in the released updates (watchOS 7.3 and tvOS 14.4).

An anonymous researcher has been credited with the reporting of all three flaws.

As per usual, Apple has decided not to share specific details about the flaws or the attack(s) they might be used for.

Zero-days exploited

Presumably, the attackers are using one or both of the WebKit flaws to execute an initial malicious payload on targeted devices, then the kernel vulnerability to achieve the necessary privileges to completely compromise the device and spy on targets’ activities.

It’s unknown whether the attacks are targeted or widespread. Apple has noted that additional details will be available soon. In the meantime, users are advised to update their devices to plug the exploited iOS zero-days.

In the last six months, similar iOS zero-days have been leveraged in targeted attacks flagged by the Google Threat Analysis Group (TAG) and Citizen Lab. The latter found them being used to install NSO Group’s Pegasus spyware.

Apple has also released a security update for iCloud for Windows that fixes four vulnerabilities that may lead to arbitrary code execution or heap corruption, and Xcode, its integrated development environment for macOS, which fixes a path handling issue that could allow a malicious application to access arbitrary files on the host device while running an app that uses on-demand resources with Xcode.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/01/27/exploited-ios-zero-days/