Spyware Vendors Caught Exploiting Zero-Day Vulnerabilities on Android and iOS Devices
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-30900 | Kernel Out-of-Bounds Write in Apple iOS, iPadOS, and macOS (Actively Exploited) CVE-2021-30900 is an out-of-bounds write (CWE-787) in the kernel of Apple iOS, iPadOS, and macOS, addressed by Apple with improved bounds checking. It is triggered locally when a user runs a malicious application crafted to exploit the flaw (CVSS local vector with user interaction required). Successful exploitation allows the attacker to execute arbitrary code with kernel privileges, effectively yielding full control of the device. Anyone running an affected build is exposed: iOS/iPadOS versions prior to 14.8.1 and 15.1, plus macOS builds listed in Apple's advisory. The bug has been exploited in the wild in commercial spyware campaigns observed by Google TAG in Italy, Malaysia, Kazakhstan, and the UAE, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30 (EPSS 5.2%, 92nd percentile; ransomware use unknown). Do: Update devices to iOS/iPadOS 14.8.1 or 15.1 (or later) and apply the corresponding macOS security update per Apple's instructions, consistent with CISA's KEV required action. Inventory mobile fleets via MDM for devices still on older builds and prioritize remediation where spyware campaigns in Italy, Malaysia, Kazakhstan, or the UAE are relevant, checking device logs for signs of compromise since these exploit chains often bundle additional flaws. | 7.8 | 5% | KEV |
| mass≈1B+ Apple devices (active iPhone/iPad/Mac installed base) | |
| CVE-2022-22706 | Unprivileged Memory-Write Flaw in Arm Mali GPU Kernel Drivers CVE-2022-22706 is a memory-safety flaw (CWE-119) in the Arm Mali GPU kernel driver that lets a local, non-privileged user gain write access to memory pages that should be read-only, potentially enabling privilege escalation or tampering with protected memory (CVSS 3.1: 7.8, local attack vector). It is triggered by a low-privileged local user interacting with the GPU driver on devices running affected Midgard (r26p0-r31p0), Bifrost (r0p0-r35p0), or Valhall (r19p0-r35p0) driver releases, which are widely shipped in Android SoCs such as those from MediaTek and HiSilicon. A successful attacker gains high confidentiality, integrity, and availability impact on the local device. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2023-03-30, and security reporting ties Mali GPU driver zero-day exploitation to commercial spyware campaigns targeting Android and iOS users in Italy, Malaysia, Kazakhstan, and the UAE. The fix reached end users through vendor firmware, including the June 2023 Android security update. Do: Apply updated Arm Mali GPU kernel drivers via your device/SoC vendor's firmware, ensuring Android endpoints are on security patch levels that include the fix (the June 2023 Android Security Bulletin shipped the Mali driver fix). Enterprises should inventory Android devices using Mali-based SoCs (e.g., MediaTek, HiSilicon) and prioritize patching devices exposed to spyware-targeted users; no workarounds are documented, and the CISA KEV required action is to apply updates per vendor instructions. | 7.8 | 1% | KEV |
| masshundreds of millions of Android devices (Mali GPUs are integrated into a large share of Android SoCs; subset running affected driver versions) | |
| CVE-2022-3038 | Use-After-Free in Chromium Network Service Affects Chrome, Edge, Opera Google Chromium's Network Service contains a use-after-free vulnerability (CWE-416) that a remote attacker can trigger via a crafted HTML page, potentially causing heap corruption in the browser process. An attacker who successfully exploits the flaw could achieve memory corruption that may lead to browser crashes or arbitrary code execution when a user visits attacker-controlled web content. Any application built on Chromium is potentially affected, including but not limited to Google Chrome, Microsoft Edge, and Opera, meaning the impact spans a very large share of the world's browser users. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2023-03-30, indicating confirmed exploitation in the wild, though ransomware association is unknown and no public proof-of-concept is cataloged. No CVSS score is available yet, but EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile), underscoring elevated exploitation risk. Do: Apply browser updates per vendor instructions immediately — update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers deployed in your environment to the latest vendor-supplied patched releases (exact fixed version numbers were not provided in this data; check each vendor's security advisory). Because the flaw is confirmed exploited in the wild and listed in CISA KEV, prioritize patching internet-facing browsing endpoints and users who routinely visit untrusted web content; there are no reliable workarounds beyond patching, though limiting browsing to trusted sites reduces exposure. | 8.8 | 25% | KEV PoC |
| mass≈3+ billion browser users across Chromium-based browsers (Chrome, Edge, Opera and derivatives) | |
| CVE-2022-3723 | Actively Exploited V8 Type Confusion in Google Chrome (CVE-2022-3723) CVE-2022-3723 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine used by Google Chrome, rated High severity with a CVSS 3.1 score of 8.8. It is triggered remotely when a user renders a crafted HTML page, allowing a remote attacker to potentially exploit heap corruption in the browser; the high confidentiality, integrity, and availability impact reflects likely code execution. All Google Chrome releases prior to 107.0.5304.87 are affected, and per CISA the underlying flaw resides in Google Chromium V8, so Chromium-based browsers embedding the same engine are similarly exposed pending their own updates. The flaw was exploited as a zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-28, and news coverage describes it as Google's ninth actively exploited Chrome zero-day of 2022, amid reports of spyware vendors exploiting zero-days in the wild. EPSS assigns a 7.9% probability (94th percentile) of exploitation activity in the next 30 days. Do: Update Google Chrome to 107.0.5304.87 or later on all endpoints and restart the browser to complete the patch, verifying the installed version via chrome://version; apply the corresponding V8/Chromium update in any Chromium-based browsers your organization ships. CISA's KEV required action is to apply updates per vendor instructions, so prioritize managed fleets, user workstations, and any browsers exposed to untrusted web content. No public PoC or workaround is known, so patching is the sole effective mitigation. | 8.8 | 8% | KEV |
| mass≈3 billion users (Chrome's global install base across desktop and mobile) | |
| CVE-2022-38181 | Use-After-Free Vulnerability in Arm Mali GPU Kernel Driver (Bifrost/Valhall/Midgard) CVE-2022-38181 is a use-after-free (CWE-416) in the Arm Mali GPU kernel driver in which GPU memory operations are mishandled, allowing unprivileged users to access freed memory. A low-privileged attacker can trigger the flaw and gain confidentiality, integrity, and availability impact (CVSS 3.1: 8.8 High), typically leveraged within exploit chains to escalate privileges in the kernel. The bug affects the Bifrost, Valhall, and Midgard Mali driver families across the version ranges listed below, meaning virtually any device running an affected Mali GPU driver is exposed, including Android smartphones such as Google Pixel devices. The vulnerability is being actively exploited: it was used in commercial spyware campaigns on Android and iOS devices reported in Italy, Malaysia, Kazakhstan, and the UAE, documented by Google TAG and GitHub Security Lab, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30. Do: Apply updates per vendor instructions as required by CISA KEV: device makers and SoC integrators should upgrade the Mali GPU kernel driver to releases newer than the affected ranges (beyond r39p0 for Bifrost/Valhall and beyond r32p0 for Midgard). End users and administrators should promptly install the latest Android/security firmware updates from their device vendor and inventory devices running affected Mali drivers for prioritized patching. | 8.8 | 14% | KEV PoC ×2 |
| masshundreds of millions to billions of devices (Mali GPUs ship in a large share of Android smartphones and embedded Arm systems) | |
| CVE-2022-4135 | Chromium GPU heap buffer overflow enables sandbox escape (affects Chrome, Edge, Opera) CVE-2022-4135 is a heap buffer overflow (CWE-787, out-of-bounds write) in the GPU process of Google Chromium, the browser engine behind Chrome and most other major browsers. It is triggered via a crafted HTML page and, per CISA, requires the attacker to have already compromised the browser's renderer process; the memory corruption in the GPU process can then be leveraged to escape the renderer sandbox. A successful attack moves the attacker out of the tightly restricted renderer sandbox toward the higher-privilege GPU process on the host, a step that can enable further code execution. All users of Chromium-based browsers are affected — CISA explicitly lists Google Chrome, Microsoft Edge, and Opera, among others — though no specific vulnerable version ranges are published in the source data. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-11-28, EPSS assigns a 31.9% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known. Do: Treat unpatched Chromium-based browsers as exposed and apply vendor updates immediately, per CISA's required action: update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers to the latest patched releases available as of the late-November 2022 KEV listing. Inventory managed endpoints for browser versions and verify auto-update is enabled, since the flaw is confirmed exploited in the wild even though no public PoC exists. | 9.6 | 32% | KEV PoC |
| mass≈billions of users across Google Chrome, Microsoft Edge, Opera and other Chromium-based browsers (exact count unknown) | |
| CVE-2022-4262 | Type Confusion in Google Chrome V8 JavaScript Engine Exploited in the Wild (CVE-2022-4262) CVE-2022-4262 is a type confusion vulnerability in the V8 JavaScript engine used by Google Chrome, in which incorrect handling of object types can lead to heap corruption. An attacker can trigger the flaw by convincing a user to visit a specially crafted HTML page, with no privileges or special network access required. Successful exploitation could allow remote code execution or information disclosure within the browser process, and the High severity rating and web-reachable attack vector reflect significant potential impact. All Google Chrome users running versions prior to 108.0.5359.94 are affected, as are users of Chromium-based browsers incorporating the vulnerable V8 code. The vulnerability was a zero-day exploited in the wild prior to the patch — attributed by media reports to commercial spyware vendors targeting Android and iOS devices — and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-12-05. Do: Update Google Chrome to 108.0.5359.94 or later on all endpoints, and apply equivalent updates from vendors of Chromium-based browsers (e.g., Microsoft Edge, Brave, Opera) as they ship patched V8 builds. Verify the fixed version is running via chrome://settings/help or your patch-management inventory, and treat browser exploit chains as a spyware risk: review endpoint telemetry for signs of compromise, especially on mobile or high-target devices. CISA's required action is to apply updates per vendor instructions. | 8.8 | 16% | KEV |
| massWell over 1 billion users (Chrome has roughly 60%+ desktop browser market share and billions of active installs; unknown how many remain on pre-108.0.5359.94… | |
| CVE-2022-42856 | Type Confusion in Apple WebKit (Safari/iOS/macOS/tvOS), Actively Exploited CVE-2022-42856 is a type confusion vulnerability (CWE-843) in Apple's WebKit web engine, addressed with improved state handling and affecting Safari, iPhone OS (iOS), iPadOS, macOS (Ventura) and tvOS. It is triggered when a user processes maliciously crafted web content, for example by visiting an attacker-controlled web page, in a WebKit-based browser or app. Successful exploitation may lead to arbitrary code execution on the affected device. Anyone running the affected Apple platforms below the December 2022 patch level (Safari 16.2, macOS Ventura 13.1, tvOS 16.2, iOS/iPadOS 15.7.2, iOS 16.1.2) was exposed, which effectively means most Apple users at the time of disclosure. Exploitation is confirmed: Apple reported the issue may have been actively exploited against iOS versions released before iOS 15.1, it was added to CISA KEV on 2022-12-14 (EPSS 8.5%, 95th percentile), and related reporting ties it to commercial spyware campaigns in Italy, Malaysia, Kazakhstan and the UAE. Do: Update immediately to Safari 16.2, macOS Ventura 13.1, tvOS 16.2, and iOS/iPadOS 15.7.2 (for iOS 15-era devices) or iOS 16.1.2 (for iOS 16-era devices), or any later release; this is a CISA KEV entry whose required action is to apply vendor updates. Because the flaw was exploited as a zero-day against iOS versions before iOS 15.1 and is linked to commercial spyware campaigns, treat patching as urgent and verify that all managed and BYOD iPhones and iPads are on a fixed version; on iOS, all third-party browsers and most web-content apps use WebKit, so the OS update itself is the remediation rather than switching browsers. | 8.8 | 9% | KEV |
| mass~1 billion+ Apple devices at disclosure (every iOS/iPadOS/macOS/tvOS device below the December 2022 patch level; Apple's active installed base exceeds 1… | |
| CVE-2023-0266 | Use-After-Free in Linux Kernel ALSA PCM Enables Local Privilege Escalation CVE-2023-0266 is a use-after-free (CWE-416) in the ALSA PCM subsystem of the Linux kernel: the SNDRV_CTL_IOCTL_ELEM_READ32 and SNDRV_CTL_IOCTL_ELEM_WRITE32 compat ioctl handlers are missing locking, so a local user can trigger access to a control element that has already been freed. An attacker with low-privilege local user access on a system with the ALSA subsystem can exploit this race to escalate privileges and gain ring0 (kernel-level) access. The flaw affects Linux kernel builds fixed by commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e, including kernels shipped in distributions such as Debian. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30, and reporting around commercial surveillance spyware campaigns (per Google TAG) indicates it was used as a zero-day in spyware exploit chains. EPSS assigns a 3.7% probability of exploitation in the next 30 days (89th percentile), and no public proof-of-concept is known. Do: Upgrade affected systems to a Linux kernel that includes fix commit 56b88b50565cd8b946a2d00b0c83927b7ebb055e, and apply vendor updates per instructions — for Debian systems, install the updated kernel packages from Debian security updates and reboot to load the patched kernel. Prioritize multi-user servers and workstations where untrusted or low-privilege local users can execute code, as this is a local privilege escalation vector with in-the-wild spyware exploitation. As interim mitigation, restrict which local users can access ALS device nodes (e.g., /dev/snd/*) or limit local account access on exposed systems. | 7.0 | 4% | KEV |
| masshundreds of millions of Linux installations broadly (kernel runs on most servers, cloud instances, and Linux desktops); practically, multi-user systems with… | |
| CVE-2023-26083 | Memory Leak Information Disclosure in Arm Mali GPU Kernel Drivers A memory leak (CWE-401) in Arm's Mali GPU kernel drivers affects Midgard (all versions r6p0-r32p0), Bifrost (all versions r0p0-r42p0), Valhall (all versions r19p0-r42p0), and Avalon (r41p0-r42p0), allowing a non-privileged local user to perform valid GPU processing operations that expose sensitive kernel metadata. A local attacker or app on an affected device gains an information-disclosure primitive that reads otherwise protected kernel memory (CVSS 3.1 base score 3.3, confidentiality impact only), potentially aiding further attacks. Exposure applies to any device whose CPU incorporates an affected Mali GPU and runs the corresponding driver, most commonly Android smartphones and tablets built on licensed Mali designs. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-07), indicating active exploitation, and Arm has issued patched drivers, with fixes also delivered through vendor/Android update channels; ransomware use is unknown. Do: Apply Arm's patched Mali kernel driver releases (versions beyond the affected ranges) via your SoC/OEM vendor, and on Android devices install the latest Google/OEM security updates, per CISA's required action. Inventory fleets for devices running affected Mali driver generations (Android phones, tablets, and embedded/edge devices) and confirm they receive the fixed driver; note that patching is mandatory for U.S. federal agencies under the KEV program despite the low severity of this local information-disclosure flaw. | 3.3 | 1% | KEV |
| masshundreds of millions of devices (order of magnitude 10^8-10^9) with licensed Mali GPUs and affected driver versions |
Full article638 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 29, 2023Zero-Day / Mobile Security
A number of zero-day vulnerabilities that were addressed last year were exploited by commercial spyware vendors to target Android and iOS devices, Google's Threat Analysis Group (TAG) has revealed.
The two distinct campaigns were both limited and highly targeted, taking advantage of the patch gap between the release of a fix and when it was actually deployed on the targeted devices. The scale of the two campaigns and the nature of the targets are currently unknown.
"These vendors are enabling the proliferation of dangerous hacking tools, arming governments that would not be able to develop these capabilities in-house," TAG's Clement Lecigne said in a new report.
"While use of surveillance technologies may be legal under national or international laws, they are often found to be used by governments to target dissidents, journalists, human rights workers, and opposition party politicians."
The first of the two operations took place in November 2022 and involved sending shortened links over SMS messages to users located in Italy, Malaysia, and Kazakhstan.
Upon clicking, the URLs redirected the recipients to web pages hosting exploits for Android or iOS, before they were redirected again to legitimate news or shipment-tracking websites.
The iOS exploit chain leveraged multiple bugs, including CVE-2022-42856 (a then zero-day), CVE-2021-30900, and a pointer authentication code (PAC) bypass, to install an .IPA file onto the susceptible device.
The Android exploit chain comprised three exploits – CVE-2022-3723, CVE-2022-4135 (a zero-day at the time of abuse), and CVE-2022-38181 – to deliver an unspecified payload.
While CVE-2022-38181, a privilege escalation bug affecting Mali GPU Kernel Driver, was patched by Arm in August 2022, it's not known if the adversary was already in possession of an exploit for the flaw prior to the release of the patch.
Another point of note is that Android users who clicked on the link and opened it in Samsung Internet Browser were redirected to Chrome using a method called intent redirection.
The second campaign, observed in December 2022, consisted of several zero-days and n-days targeting the latest version of Samsung Internet Browser, with the exploits delivered as one-time links via SMS to devices located in the U.A.E.
The web page, similar to those that were used by Spanish spyware company Variston IT, ultimately implanted a C++-based malicious toolkit capable of harvesting data from chat and browser applications.
The flaws exploited constitute CVE-2022-4262, CVE-2022-3038, CVE-2022-22706, CVE-2023-0266, and CVE-2023-26083. The exploit chain is believed to have been used by a customer or partner of Variston IT.
Amnesty International, in a coordinated report, described the December 2022 hacking campaign as advanced and sophisticated and that the exploit is "developed by a commercial cyber surveillance company and sold to governments hackers to carry out targeted spyware attacks."
"The newly discovered spyware campaign has been active since at least 2020 and targeted mobile and desktop devices, including users of Google's Android operating system," the international non-governmental organization said. "The spyware and zero-day exploits were delivered from an extensive network of more than 1,000 malicious domains, including domains spoofing media websites in multiple countries."
The revelations come just days after the U.S. government announced an executive order restricting federal agencies from using commercial spyware that presents a national security risk.
"These campaigns are a reminder that the commercial spyware industry continues to thrive," Lecigne said. "Even smaller surveillance vendors have access to zero-days, and vendors stockpiling and using zero-day vulnerabilities in secret pose a severe risk to the Internet."
"These campaigns may also indicate that exploits and techniques are being shared between surveillance vendors, enabling the proliferation of dangerous hacking tools."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/03/spyware-vendors-caught-exploiting-zero.html