Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Apple emergency updates fix 3 new zero-days exploited in attacks
#1
https://www.bleepingcomputer.com/news/ap...n-attacks/      Apple emergency updates fix 3 new zero-days exploited in attacks
By Sergiu Gatlan
September 21, 2023 01:57 PM      Apple released emergency security updates to patch three new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 16 zero-days fixed this year.

Two bugs were found in the WebKit browser engine (CVE-2023-41993) and the Security framework (CVE-2023-41991), enabling attackers to bypass signature validation using malicious apps or gain arbitrary code execution via maliciously crafted webpages.

The third one was found in the Kernel Framework, which provides APIs and support for kernel extensions and kernel-resident device drivers. Local attackers can exploit this flaw (CVE-2023-41992) to escalate privileges.

Apple fixed the three zero-day bugs in macOS 12.7/13.6, iOS 16.7/17.0.1, iPadOS 16.7/17.0.1, and watchOS 9.6.3/10.0.1 by addressing a certificate validation issue and through improved checks.

"Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7," the company revealed in security advisories describing the security flaws.

The list of impacted devices encompasses older and newer device models, and it includes:

iPhone 8 and later
iPad mini 5th generation and later
Macs running macOS Monterey and newer
Apple Watch Series 4 and later
All three zero-days were found and reported by Bill Marczak of the Citizen Lab at The University of Toronto's Munk School and Maddie Stone of Google's Threat Analysis Group.

While Apple has yet to provide additional details regarding the flaws' exploitation in the wild, Citizen Lab and Google Threat Analysis Group security researchers have often disclosed zero-day bugs abused in targeted spyware attacks targeting high-risk individuals, including journalists, opposition politicians, and dissidents.

Citizen Lab disclosed two other zero-days (CVE-2023-41061 and CVE-2023-41064), also fixed by Apple in emergency security updates earlier this month and abused as part of a zero-click exploit chain (dubbed BLASTPASS) to infect fully patched iPhones with NSO Group's Pegasus commercial spyware.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  VMware warns of critical vRealize flaw exploited in attacks mrtrout 0 407 06-21-2023 , 02:00 AM
Last Post: mrtrout
  Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks mrtrout 0 637 10-11-2021 , 09:47 PM
Last Post: mrtrout
  Top Linux Vulnerabilities Exploited by Hackers mrtrout 0 530 08-27-2021 , 01:12 AM
Last Post: mrtrout
  At least 10 APT hacking groups have exploited Exchange Server bugs, ESET warns Bjyda 0 1,064 03-11-2021 , 10:36 PM
Last Post: Bjyda
  Apple fixes three iOS zero-days exploited in the wild mrtrout 0 1,042 11-06-2020 , 02:47 AM
Last Post: mrtrout

Forum Jump:


Users browsing this thread: 1 Guest(s)