Report: Mercenary spyware exploited Google Chrome zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-2294 | Heap Buffer Overflow in Google Chrome WebRTC Exploited in the Wild CVE-2022-2294 is a heap buffer overflow (out-of-bounds write, CWE-787) in the WebRTC component used by Google Chrome. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, and successful exploitation allows heap corruption with potential arbitrary code execution (CVSS 3.1: 8.8, high impact on confidentiality, integrity and availability). It affects Chrome prior to 103.0.5060.114 and, because the vulnerable code path resides in the shared WebRTC/WebKit component, it also affects Apple's iPhone OS, iPadOS, macOS/Mac OS X, tvOS and watchOS, WebKitGTK, WPE WebKit, Fedora and Extra Packages for Enterprise Linux (EPEL), and the WebRTC project library itself. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-25 with known ransomware use, and reporting indicates mercenary spyware operators used it as a Chrome zero-day; EPSS places its 30-day exploitation probability at 70.5%. Google fixed the flaw in Chrome 103.0.5060.114, and Apple and the WebKit/WPE maintainers issued their own security updates for affected products. Do: Upgrade Google Chrome to 103.0.5060.114 or later on all managed and personal endpoints immediately. Apply Apple's released security updates for iPhone OS, iPadOS, macOS, tvOS and watchOS, and updated WebKitGTK, WPE WebKit and Fedora/EPEL packages for WebKit-based deployments. Given the CISA KEV listing, known ransomware use and 70.5% EPSS, prioritize patching and hunt for signs of exploitation (crafted-page lures and any linked spyware or ransomware activity) across browsers and WebKit applications. | 8.8 | 70% | KEV ransomware |
| mass≈3+ billion Chrome users worldwide, plus additional users of Apple WebKit devices, WebKitGTK, WPE WebKit and Fedora/EPEL browser packages |
Full article476 words · extracted from therecord.media · click to collapse
A zero-day vulnerability in Google Chrome was discovered when attackers exploited it to target users in the Middle East, including journalists, cybersecurity firm Avast said Thursday. The company attributed the attacks to a secretive Israeli firm known as Candiru — named after a notorious parasitic fish — that sells spyware to governments. Candiru has been active for years, but drew added scrutiny after University of Toronto’s Citizen Lab and Microsoft exposed the firm’s links to the DevilsTongue malware last July and laid out how the tool had been used to target members of civil society. The U.S. government sanctioned Candiru along with several other makers of hacking tools sold to governments later that year. This April, Citizen Lab also linked Candiru tools to attacks targeting members of the Catalan community in Spain. Candiru appeared to lay low after the first Citizen Lab report, likely to develop new exploits, according to Avast. Then it re-emerged. “We’ve seen it return with an updated toolset in March 2022, targeting Avast users located in Lebanon, Turkey, Yemen, and Palestine via watering hole attacks using zero-day exploits for Google Chrome,” Avast wrote. “We believe the attacks were highly targeted.” Watering hole attacks are when attackers lure victims to compromised websites that can infect their machines. In this case, the attackers used a chain of exploits to target victims that included a zero-day vulnerability in Google Chrome. Google released a fix for the issue (CVE-2022-2294) in a July 4 update. Avast wrote that “a large portion” of the attacks it observed took place in Lebanon, where “the attackers seem to have compromised a website used by employees of a news agency.” Journalists are a frequent target of attacks by nation-state actors, often for intelligence purposes. “We can’t say for sure what the attackers might have been after, however often the reason why attackers go after journalists is to spy on them and the stories they’re working on directly, or to get to their sources and gather compromising information and sensitive data they shared with the press,” Avast wrote. Bill Marczak, one of the authors of Citizen Lab’s investigations into Candiru, told The Record the Avast report demonstrates the value of having more security firms on the alert for mercenary spyware. “At least five security companies, including Avast, have detected, burned, and published on Candiru attacks directed against their customers running Microsoft Windows,” he said. However, Marczak added, researchers may have only scratched the surface. “Candiru also appears to maintain capabilities against mobile phones, but none of these has been detected, as far as we know,” he added.
No previous article
No new articles
Andrea Peterson
(they/them) is a longtime cybersecurity journalist who cut their teeth covering technology policy at ThinkProgress (RIP) and The Washington Post before doing deep-dive public records investigations at the Project on Government Oversight and American Oversight.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/report-mercenary-spyware-exploited-google-chrome-zero-day-to-target-journalists