Apple released iOS 17.2 to address a dozen of security flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-42890 | The issue was addressed with improved memory handling. The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution. NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2023-42898 | The issue was addressed with improved memory handling. The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing an image may lead to arbitrary code execution. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-42917 +1 in the same advisory: …42916 | WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile). Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users. | 8.8 group max | 9% | KEV |
| masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base) |
Full article205 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 12, 2023

Apple rolled out emergency security updates to backport patches for two actively exploited zero-day flaws to older devices.
The company released iOS 17.2 and iPadOS 17.2 which address a dozen of security flaws.
The most severe flaw is a memory corruption issue that resides in the ImageIO. Successful exploitation of the flaw may lead to arbitrary code execution. The IT giant addressed the flaw by improving memory handling.
The flaw CVE-2023-42898 was discovered by Junsung Lee.
Apple also addressed a code execution flaw, tracked as CVE-2023-42890, in the WebKit. Processing web content may lead to arbitrary code execution.
Apple this week rolled out emergency security updates to backport patches for two actively exploited zero-day flaws to older devices. The company released iOS 16.7.3 and iPadOS 16.7.3 to address known flaws in older versions of the operating system.
Addressed issues include CVE-2023-42916 and CVE-2023-42917 which Apple fixed at the end of November.
Clément Lecigne of Google’s Threat Analysis Group discovered both vulnerabilities. The fact that the issues were discovered by Google TAG suggests they were exploited by a nation-state actor or by a surveillance firm.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Apple)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/155669/security/apple-released-ios-17-2.html