ZeroHour
The Recordpublished ()ingested

Zero-days exploited in the wild jumped 50% in 2023, fueled by spyware vendors

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-4863CVE-2023-41064CVE-2023-5217

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41064
ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution

CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs.

Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices.

7.845% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion)
CVE-2023-4863
Out-of-Bounds Write in Google Chromium WebP Image Codec Actively Exploited

CVE-2023-4863 is a heap-based buffer overflow (CWE-787) in the WebP image codec used by Google Chromium, allowing a remote attacker to write outside the intended bounds of allocated memory. It is triggered when a user visits a crafted HTML page containing malicious WebP image data, so no authentication or special privileges are required, only that the victim loads attacker-controlled content in an affected application. Successful exploitation gives the attacker an out-of-bounds memory write in the affected process, which can lead to application crashes or memory corruption with the potential for code execution. Exposure is unusually broad because, per the advisory, the flaw can affect any application that uses the WebP codec, meaning the browsing public and any software bundling WebP decoding are plausibly in scope. The flaw was added to the CISA KEV catalog on 2023-09-13, indicating confirmed exploitation in the wild; EPSS assigns it a 100% probability of exploitation within 30 days, ransomware use is unknown, and no public proof-of-concept is known.

Do: Update Google Chrome and all other Chromium-based browsers to the latest stable release containing the WebP fix (the patched Chrome 116.0.5845.187 shipped in September 2023), and update or rebuild any other software that bundles the WebP/libwebp codec (fixed in libwebp 1.3.2). Until patching is complete, treat untrusted web content as the attack vector and, per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of affected software if mitigations are unavailable. Verify remediation by checking installed browser and application versions against the vendor advisories.

8.8100% KEV PoC ×4
  • Google Chromium WebP
mass~3+ billion users (Chromium-based browsers account for roughly two-thirds of global browser usage)
CVE-2023-5217
Heap Buffer Overflow in Google Chromium libvpx (CVE-2023-5217) Added to CISA KEV

CVE-2023-5217 is a heap buffer overflow (CWE-787) in the VP8 encoding path of libvpx, the open-source video codec library bundled with Google's Chromium/Chrome browser. A remote attacker can trigger the flaw by luring a user to a crafted HTML page whose web content invokes the vulnerable VP8 encoding code, corrupting the heap and potentially achieving code execution in the affected browser. Anyone running Google Chrome/Chromium — or other browsers and software that embed libvpx, as CISA notes the library's use is 'not limited to Google Chrome' — is affected. Exploitation is confirmed: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-10-02 (ransomware association: unknown), though no public proof-of-concept is available and a CVSS score has not been published; EPSS puts the 30-day exploitation probability at 49% (99th percentile). Defenders should treat this as an actively exploited browser vulnerability requiring prompt patching.

Do: Update Chrome/Chromium to the vendor release that fixes CVE-2023-5217 — Google shipped the fix with its late-September 2023 stable-channel security update, so verify the exact build number in Google's advisory (it is not specified in the source data). Also patch any other products bundling libvpx (other browsers, media/ffmpeg-based tooling) per vendor instructions, and ensure KEV compliance by applying the required mitigations or discontinuing use of affected builds by the CISA deadline.

8.849% KEV PoC
  • Google Chromium libvpx (VP8 encoding component, as bundled in Chrome/Chromium)
  • Google Chrome (browser shipping Chromium libvpx)
masson the order of 1–3+ billion users/devices (Chrome's global installed base; roughly two-thirds desktop browser market share)
Full article1,004 words · extracted from therecord.media · click to collapse

Cybersecurity experts are warning that zero-day exploits, which can be used to compromise devices before anyone is aware they’re vulnerable, have become more common as nation-state hackers and cybercriminals find sophisticated ways to carry out their attacks.

Researchers from Google on Wednesday said they observed 97 zero-days exploited in the wild in 2023, compared to 62 in 2022 — a 50 percent increase. 

Of the 97 zero-days, the researchers were able to attribute the threat actors’ motivations for 58 of them. Fourty-eight of the vulnerabilities were attributed to espionage actors while the remaining 10 were attributed to financially-motivated hackers. 

Three zero-days were exploited by FIN11, and four ransomware gangs — Nokoyawa, Akira, LockBit and Magniber — separately exploited another four. The report notes that FIN11 was behind the 2021 zero-day affecting Accellion’s legacy File Transfer Appliance that was used to attack dozens of high profile institutions. 

“FIN11 has focused heavily on file transfer applications which provide efficient and effective access to sensitive victim data without the need for lateral network movement, streamlining the steps for exfiltration and monetization,” the researchers said.  

“Subsequently, the large revenues generated from mass extortion or ransomware campaigns likely fuels additional investment by these groups in new vulnerabilities.”

Beijing-linked hackers who were focused on espionage were behind 12 zero-days, up from seven in 2022.

The researchers reported extensively on several Chinese campaigns — including the explicit targeting of Barracuda’s Email Security Gateway — with hackers targeting email domains and users from Ministries of Foreign Affairs of ASEAN member nations as well as individuals within foreign trade offices and academic research organizations in Taiwan and Hong Kong.

Google noted that one zero-day was tied to Winter Vivern, a Belarusian state sponsored cyber group behind several attacks on Ukraine and other European countries. Google said it is the first known instance of reportedly Belarusian-linked espionage groups leveraging zero-day vulnerabilities in their campaigns, suggesting the group “is growing in sophistication.”

In terms of products that were targeted, the researchers found that threat actors sought “vulnerabilities in products or components that provided broad access to multiple targets of choice.”

Enterprise-specific technologies like Barracuda Email Security Gateway, Cisco Adaptive Security Appliance, Ivanti Endpoint Manager Mobile and Sentry and Trend Micro Apex One were repeatedly targeted, the researchers said, adding that these products typically provide widespread access and high-level permissions.

Commercial spyware vendors

This increase in exploitation of enterprise-specific technologies in 2023 was driven mainly by the exploitation of security software and appliances. 

Commercial surveillance vendors (CSVs) were the leading culprit behind browser and mobile device exploitation, with Google attributing 75% of known zero-day exploits targeting Google products as well as Android ecosystem devices in 2023 (13 of 17 vulnerabilities).

Maddie Stone, a researcher with TAG, said the most alarming part of Google’s zero-day findings was the high volume of vulnerabilities being exploited in the wild by CSVs and lack of global norms against the industry. 

“We have widely documented the harm CSVs cause and yet they continue to make up the majority of in-the-wild 0-days targeting end-users,” she said.

The tech giant reiterated its warning that the commercial surveillance industry continues to sell cutting edge technology to governments around the world that exploit vulnerabilities in consumer devices and applications “to surreptitiously install spyware on individuals’ devices.”

“Private sector firms have been involved in discovering and selling exploits for many years, but we have observed a notable increase in exploitation driven by these actors over the past several years,” they said. 

Google said in February that it is tracking at least 40 companies involved in the creation of spyware and other hacking tools that are sold to governments and deployed against “high risk” users, including journalists, human rights defenders and dissidents.

Intra-browser attacks

Google also noted that vulnerabilities in third party components and libraries are “a prime attack surface since they can often affect more than one product.”

In 2023, Google saw this kind of targeting increase in 2023, particularly with browsers. They saw three browser zero-days exploited that were in third party components and affected more than one browser.

The report notes that CVE-2023-4863 affecting Chrome and CVE-2023-41064 affecting Safari are “actually the same bug” — adding that it also affected Android and Firefox. They also cited CVE-2023-5217 — a headline-grabbing vulnerability that emerged last year affecting libvpx. Several other intra-browser tools were exploited last year as well. 

Surprisingly, last year there were no in-the-wild zero-days detected that targeted macOS. Google explained that while some of the iOS vulnerabilities identified did also affect macOS due to shared components, the discovered exploit only targeted iPhones. 

“In 2023 there were eight in-the-wild zero-days targeting Chrome and 11 targeting Safari. While the tracked Safari zero-days were used in chains targeting iPhones, all except for one of the Chrome zero-days were used in chains targeting Android devices,” the researchers said.

Google warned that it is likely the number of exploited zero-days will continue to increase as more hackers invest heavily in research. 

Zero-day exploitation is “no longer just a niche capability accessible to only a handful of actors, and we anticipate that the growth we have seen across the last few years will likely continue, as vendors continue to make other avenues of compromise less accessible and as threat actors focus increasing resources on zero-day exploitation.”

TAG’s Stone told Recorded Future News that the most promising findings from the report were vendor mitigations like Google’s MiraclePtr and Apple’s Lockdown mode, both of which successfully prevent exploitation of many exploit chains used in-the-wild.

“This demonstrates how vendor investments in security can have demonstrable impact on making it more difficult for attackers to exploit users with zero-days,” she added.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/zero-day-exploits-jumped-in-2023-spyware