ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple patches two zero-days used to target iOS users (CVE-2023-42916 CVE-2023-42917)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-42917
+1 in the same advisory: …42916
WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution

CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).

Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.

8.8
group max
9% KEV
  • apple iphone os (iOS) versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1
  • apple ipados versions prior to iPadOS 17.1.2
  • apple macos (Sonoma) versions prior to macOS Sonoma 14.1.2
  • +4 more
masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base)
Full article308 words · extracted from helpnetsecurity.com · click to collapse

With the latest round of security updates, Apple has fixed two zero-day WebKit vulnerabilities (CVE-2023-42916, CVE-2023-42917) that “may have been exploited against versions of iOS before iOS 16.7.1.”

CVE-2023-42916 CVE-2023-42917

About the vulnerabilities (CVE-2023-42916, CVE-2023-42917)

CVE-2023-42916 is a out-of-bounds read flaw, while CVE-2023-42917 is a vulnerability allowing for exploitable memory corruption.

Both affect WebKit, the Apple-developed browser engine used by the company’s Safari web browser and all web browsers on iOS and iPadOS.

CVE-2023-42916 may lead to disclosure of sensitive information, while CVE-2023-42917 allows arbitrary code execution. Both flaws can be triggered by Safari processing specially crafted web content.

Fixes are available

The vulnerabilities have been reported to Apple by security researcher Clément Lecigne, of Google’s Threat Analysis Group (TAG).

As is their wont, Apple did not disclose details about the attacks in which these zero-days have been exploited, but we know that Google TAG often uncovers zero-day vulnerabilities used to deliver state-sponsored spyware to targeted individuals (political dissidents, activists, and journalists).

Security updates with fixes for the two vulnerabilities are available for:

While the vulnerabilities have likely been exploited in extremely targeted attacks, all users are advised to implement these updates as soon as possible.

Apple says that vulnerabilities have been exploited against versions of iOS before 16.7.1, but does not say whether iOS 16.7.1 and iOS 16.7.2 (the most recent iOS 16 release) are vulnerable. If they are, Apple will likely soon push out new security updates for the iOS 16.

UPDATE (December 12, 2023, 04:50 a.m. ET):

Apple has backported the patches for CVE-2023-42916 and CVE-2023-42917 to iOS and iPadOS 16.7.3, and has added them to tvOS 17.2 and watchOS 10.2.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/12/01/cve-2023-42916-cve-2023-42917/