ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New Tool Can Jailbreak Any iPhone and iPad Using An Unpatched 0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-8605
Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution

CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept.

Do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application.

7.818% KEV
  • apple iphone os (iOS) versions prior to iOS 12.3 (fixed in iOS 12.3)
  • apple mac os x (macOS Mojave) versions prior to macOS Mojave 10.14.5 (fixed in 10.14.5)
  • apple tvos versions prior to tvOS 12.3 (fixed in tvOS 12.3)
  • +1 more
masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact…
Full article502 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 25, 2020

The hacking team behind the "unc0ver" jailbreaking tool has released a new version of the software that can unlock every single iPhone, including those running the latest iOS 13.5 version.

Calling it the first zero-day jailbreak to be released since iOS 8, unc0ver's lead developer Pwn20wnd said "every other jailbreak released since iOS 9 used 1day exploits that were either patched in the next beta version or the hardware."

The group did not specify which vulnerability in iOS was exploited to develop the latest version.

The unc0ver website also highlighted the extensive testing that went behind the scenes to ensure compatibility across a broad range of devices, from iPhone 6S to the new iPhone 11 Pro Max models, spanning versions iOS 11.0 through iOS 13.5, but excluding versions 12.3 to 12.3.2 and 12.4.2 to 12.4.5.

"Utilizing native system sandbox exceptions, security remains intact while enabling access to jailbreak files," according to unc0ver, meaning installing the new jailbreak will likely not compromise iOS' sandbox protections.

Jailbreaking, analogous to rooting on Google's Android, is a privilege escalation that works by exploiting flaws in iOS to grant users root access and full control over their devices. This allows iOS users to remove software restrictions imposed by Apple, thereby allowing access to additional customization and otherwise prohibited apps.

But it also weakens the device's security, opening the door to all kinds of malware attacks. The added security risks, coupled with Apple's steady hardware and software lockdown, have made it difficult to jailbreak devices deliberately.

Furthermore, jailbreaks tend to be very specific and based on previously disclosed vulnerabilities, and very much dependent on the iPhone model and iOS version, in order for them to be successfully replicated.

The development comes as zero-day exploit broker Zerodium said it would no longer purchase iOS RCE vulnerabilities for the next few months, citing "a high number of submissions related to these vectors."

Last August, Pwn20wnd exploited a SockPuppet flaw (CVE-2019-8605) uncovered by Googler Ned Williamson to release a public version of the jailbreak — making it the first time an up-to-date firmware was unlocked in years — after Apple accidentally reintroduced a previously patched flaw in iOS 12.4. The company later rolled out a fix in iOS 12.4.1 to address the privilege escalation vulnerability.

Then in September, a security researcher published details of a permanent unpatchable bootrom exploit, dubbed checkm8, that could be employed to jailbreak virtually every type of Apple mobile device released between 2011 and 2017, including iPhones, iPads, Apple Watches, and Apple TVs.

While the new jailbreak leverages an as-yet-unknown zero-day vulnerability, the iPhone maker will likely roll out a security update in the coming weeks to plug the flaw exploited by unc0ver.

The new Unc0ver 5.0.0 jailbreak can be installed from iOS, macOS, Linux, and Windows devices. The usage instructions are available on the unc0ver website here.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/05/iphone-ios-jailbreak-tools.html