Site navigation

Apple Patches Three Zero-Day Vulnerabilities

Michael Edgar

,

Apple zero-day patch
Apple has patched three exploited zero-day vulnerabilities used to distribute spyware called triangulation. The exploit serves as a reminder to keep your iOS up to date. 

The discoveries were made by security researchers Georgy Kucherin, Leonid Bezvershenko, and Boris Larin at Kaspersky.

They explain in a blog post how the implant known as TriangleDB is deployed on an iOS device after attackers exploited a kernel vulnerability to gain root privileges. 

A zero-day vulnerability refers to a security flaw in a software that is unknown to the software developer – meaning developers have “zero-days” to fix it before it is exploited by attackers. 

The two found by Kaspersky researchers are identified as CVE-2023-32434 and CVE-2023-32435. The former involves a kernel bug that could lead to unauthorised access, while the latter is a WebKit bug which enables remote code execution (RCE) when processing web content. 

An anonymous researcher identified the third vulnerability known as CVE-2023-32439 which, like CVE-2023-32435, is an RCE that can be triggered by crafted web content and may have been exploited. 

The TriangleDB implant which is deployed through the kernel vulnerability is deployed in memory. This means that all traces of the implant are lost when the device is rebooted. Attackers have to reinfect the device from the start by sending an iMessage, which may not even need user interaction to work. 

The implant’s capabilities include interacting with the filesystem by creating, modifying, exfiltrating and removing files, as well as listening and terminating processes, accessing the keychain (passwords), and monitoring user location.

According to Apple, the kernel affected watchOS 8.8.1 and 9.5.2, macOS Big Sur 11.7.8, macOS Monterey 12.6.7, iOS 16.5.1, and iPadOS 16.5.1. The WebKit bug and the kernel bug both impact macOS Ventura 13.4.1, iOS 15.7.7, and iPadOS 15.7.7.

Device-wise, the kernel and WebKit could be found in all iPhone 6s models, all iPhone 7 models, iPhone SE 1st generation, iPad Air 2, iPad mini 4th generation, and iPod touch 7th generation.


Recommended


Ray Kelly, fellow at the Synopsys Software Integrity Group said: “Security-focused updates like this really stress the importance of enabling automatic iOS updates to ensure you have the latest software that keeps your device safe. However, since some users choose to disable these automatic updates, malicious actors will always have a vast amount of vulnerable targets.”

Apple responded to these zero-day vulnerabilities yesterday in its newest iOS update, and urged all affected users to update their devices to the latest software versions to mitigate the risks associated with these exploits.

“Apple has a great track record when it comes to addressing critical vulnerabilities in its software quickly to help its users stay protected. This is critically important since Apple users do not have a way to protect themselves from malicious websites that may be actively exploiting in the wild, like this specific WebKit vulnerability,” said Kelly.

Tags: , , ,

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data