ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

US Government Ordered to Urgently Patch Apple Zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-41064CVE-2023-41061

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41061
Actively Exploited Wallet Flaw Enables Code Execution on Apple iOS, iPadOS, watchOS

Apple patched an input validation flaw (CVE-2023-41061, CWE-20) in the Wallet component of iOS, iPadOS, and watchOS that can allow arbitrary code execution when a user interacts with a maliciously crafted attachment. The attack is local and requires user interaction (CVSS 7.8, AV:L/UI:R), so the victim must open or act on the crafted attachment — typically delivered through messaging or another application — for the exploit to succeed. A successful attack yields code execution on the device, and media reports describe it as having been used in 'extremely sophisticated attacks' chained with other Apple zero-days. Anyone running iPhone OS (iOS), iPadOS, or watchOS versions prior to iOS/iPadOS 16.6.1 and watchOS 9.6.2 is affected, a population on the order of a billion active devices. Apple disclosed the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2023-09-11.

Do: Immediately update iPhones and iPads to iOS/iPadOS 16.6.1 or later, and Apple Watch to watchOS 9.6.2 or later. Because the flaw is listed in CISA's KEV catalog and was actively exploited at disclosure, treat patching as urgent for all user fleets, especially high-value targets; until patched, exercise caution with attachments from untrusted sources. No public proof-of-concept is known, but defenders should check fleet OS versions for stragglers on pre-16.6.1 builds.

7.84% KEV
  • Apple iPhone OS (iOS) all versions prior to 16.6.1
  • Apple iPadOS all versions prior to 16.6.1
  • Apple watchOS all versions prior to 9.6.2
massover 1 billion active devices (combined iPhone/iPad/Apple Watch fleet not yet patched)
CVE-2023-41064
ImageIO Buffer Overflow in Apple iOS, iPadOS, and macOS Allows Code Execution

CVE-2023-41064 is a buffer overflow (CWE-120) in the ImageIO component of Apple iOS, iPadOS, and macOS that is triggered when the system processes a maliciously crafted image. Because ImageIO performs image decoding for messaging and web content, an attacker can reach the flaw through attachments or web pages, and successful exploitation may allow arbitrary code execution on the device. The flaw was exploited in the wild as part of a chain with CVE-2023-41061 (WebKit), which public reporting described as a zero-click, spyware-grade compromise chain used against civil-society targets. All users of iPhones, iPads, and Macs running builds released before Apple's September 2023 fixes are affected, making the exposed population extremely large. The vulnerability was added to the CISA KEV catalog on 2023-09-11, carries a high EPSS score of 45.1% (99th percentile), and no standalone public proof-of-concept is known because exploitation is occurring in real-world attacks rather than labs.

Do: Apply Apple's September 2023 fixes — iOS and iPadOS 16.6.1 or later and macOS Ventura 13.5.2 or later — across all iPhone, iPad, and Mac fleets, which satisfies the CISA KEV required action. Because the observed in-the-wild chain paired this ImageIO bug with the CVE-2023-41061 WebKit flaw, treat unpatched devices as actively targeted and prioritize high-value users and privileged endpoints. If updates cannot be deployed promptly, follow the KEV guidance to apply vendor mitigations or discontinue use of the affected devices.

7.845% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's installed base of active iPhones, iPads, and Macs exceeds 1 billion)
Full article306 words · extracted from infosecurity-magazine.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies less than a month to update their iOS, iPadOS and macOS devices in order to mitigate the risk of spyware attacks.

CISA added two recently discovered Apple zero-day flaws to its Known Exploited Vulnerabilities Catalog, stating that agencies have until October 2 to patch them through official vendor updates, or else discontinue using the products.

CVE-2023-41064 is described as a buffer overflow vulnerability in ImageIO, which occurs when processing a maliciously crafted image and may lead to code execution. It is chained with CVE-2023-41061, a validation issue in Apple Wallet in which a maliciously crafted attachment may result in code execution.

The bugs were discovered by Citizen Lab last week after the non-profit warned that they were used in an exploit chain it dubbed “BlastPass,” to deliver the notorious Pegasus spyware to an employee of a Washington-based civil society organization.

Read more on Pegasus: Spanish Ombudsman to Probe Pegasus Spyware Claims

Citizen Lab claimed the exploit used PassKit attachments containing malicious images sent via iMessage.

It’s unclear who authorized the attacks on that individual, but if it’s a hostile nation, the concern will be that they could also be used to target US government officials.

Back in 2021, reports revealed that nine US State Department officials had their iPhones remotely hacked by spyware from the same source: controversial commercial malware developer NSO Group.

Apple is suing the Israeli firm in a bid to hold it accountable for the actions of some unscrupulous clients. NSO Group has always maintained that it only sells its wares for legitimate law enforcement and intelligence gathering purposes.

NSO Group was also put on a US Entity List back in 2021, theoretically making it harder for the firm to get hold of American components or work with US partners.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/us-government-ordered-patch-apple/