Threat Advisory

Apple Releases Patches for Actively Exploited macOS and Safari

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

 

Summary: [/subscribe_to_unlock_form]

 

Summary: [emaillocker id="1283"]

Apple has released a series of updates addressing several security vulnerabilities in its software products, including macOS and the Safari browser. These vulnerabilities were actively exploited by threat actors, prompting the urgent need for patching.

  • CVE-2023-32434 is an integer overflow flaw in the Kernel, enabling a malicious app to execute arbitrary code with kernel privileges.
  • CVE-2023-32435 is a memory corruption vulnerability in WebKit, which may result in arbitrary code execution when processing specifically crafted web content.

The affected MacOS versions are Ventura 13.4.1, Monterey 12.6.7, and Big Sur 11.7.8. The exploit code is designed to download additional components, acquiring root privileges on the targeted device. Subsequently, a backdoor is deployed in memory, and the initial iMessage is erased to hide any traces of the infection. These activities encompass interacting with the device's file system (such as creating, modifying, exfiltrating, and deleting files), managing processes (listing and terminating them), extracting keychain items to gather victim credentials, and monitoring the victim's geolocation, among other actions.

Apple has also addressed a third zero-day vulnerability, identified as CVE-2023-32439, which was reported anonymously. This flaw could potentially lead to arbitrary code execution when handling malicious web content. Apple has resolved the actively exploited flaw, characterized as a type confusion problem, by implementing enhanced checks.

 

Recommendations:

We strongly recommend you update the following products to the given version.

  • macOS Ventura to version 13.4.1
  • macOS Big Sur to version 11.7.8
  • macOS Monterey to version 12.6.7
  • Safari to version 16.5.1

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html

[/emaillocker]
crossmenu