Apple Issues Emergency Patches for More Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-42824 | Kernel Privilege Escalation in Apple iOS and iPadOS (Actively Exploited) CVE-2023-42824 is a privilege escalation vulnerability in the kernel of Apple's iOS and iPadOS, addressed with improved checks in iOS 16.7.1 and iPadOS 16.7.1. It is triggered locally: an attacker who can already run code on the device (for example via a malicious app or as one stage of a chained attack) exploits the flaw to elevate privileges. Successful exploitation grants kernel-level privilege, with high confidentiality, integrity, and availability impact, meaning near-full control of the affected device. Any iPhone or iPad running iOS/iPadOS versions prior to 16.7.1 is affected, and Apple reported the issue was being actively exploited against iOS versions before 16.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-05 with no public PoC listed, making patching urgent. Do: Update affected iPhones and iPads to iOS 16.7.1 / iPadOS 16.7.1 or later (any subsequent iOS release includes the fix), and verify device versions via Settings > General > Software Update. There is no indicated workaround, so prioritize patching for high-risk users (executives, admins, journalists), since local kernel elevation bugs of this kind are commonly chained with remote code execution or sandbox-escape exploits. Per CISA's required action, apply the vendor updates promptly or restrict use of unpatched devices. | 7.8 | <1% | KEV |
| masshundreds of millions of consumer devices (Apple's active iPhone/iPad installed base exceeds 1 billion) | |
| CVE-2023-5217 | Heap Buffer Overflow in Google Chromium libvpx (CVE-2023-5217) Added to CISA KEV CVE-2023-5217 is a heap buffer overflow (CWE-787) in the VP8 encoding path of libvpx, the open-source video codec library bundled with Google's Chromium/Chrome browser. A remote attacker can trigger the flaw by luring a user to a crafted HTML page whose web content invokes the vulnerable VP8 encoding code, corrupting the heap and potentially achieving code execution in the affected browser. Anyone running Google Chrome/Chromium — or other browsers and software that embed libvpx, as CISA notes the library's use is 'not limited to Google Chrome' — is affected. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-10-02 (ransomware association: unknown), though no public proof-of-concept is available and a CVSS score has not been published; EPSS puts the 30-day exploitation probability at 49% (99th percentile). Defenders should treat this as an actively exploited browser vulnerability requiring prompt patching. Do: Update Chrome/Chromium to the vendor release that fixes CVE-2023-5217 — Google shipped the fix with its late-September 2023 stable-channel security update, so verify the exact build number in Google's advisory (it is not specified in the source data). Also patch any other products bundling libvpx (other browsers, media/ffmpeg-based tooling) per vendor instructions, and ensure KEV compliance by applying the required mitigations or discontinuing use of affected builds by the CISA deadline. | 8.8 | 49% | KEV PoC |
| masson the order of 1–3+ billion users/devices (Chrome's global installed base; roughly two-thirds desktop browser market share) |
Full article319 words · extracted from infosecurity-magazine.com · click to collapse
Apple has been forced to issue more emergency updates to fix two new zero-day vulnerabilities impacting iOS and iPadOS users.
An advisory published on Wednesday described CVE-2023-42824 as a kernel issue which could allow a local attacker to elevate their privileges. It was addressed with improved checks.
“Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6,” the tech giant added.
The second zero-day vulnerability, CVE-2023-5217, affects the WebRTC open source communications software and could lead to a buffer overflow resulting in arbitrary code execution. It was fixed by updating the libvpx video codec library to version 1.13.1, Apple said.
Both patches are part of the iOS 17.0.3 and iPadOS 17.0.3 update and are available for iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later.
There’s no information as to who discovered the zero-day bugs, so it is unclear whether they may have been used to deliver commercial spyware.
Apple has been forced to patch a slew of zero-days in recent weeks which were discovered by Google and the non-profit Citizen Lab, which have a track record of unearthing state-sponsored threats connected to such operations.
At the end of September, Apple patched three of these, including bugs in its kernel, security framework and WebKit browser engine. They were linked to the Predator spyware from Cytrox.
At the start of the same month, it fixed two more linked to the delivery of the notorious Pegasus spyware developed by NSO Group.
This brings the total number of zero-days patched by Apple to 17 for the year so far.
Image credit: Shahid Jamil / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/apple-issues-emergency-patches/