Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
Apple has released a series of updates addressing several security vulnerabilities in its software products, including macOS and the Safari browser. These vulnerabilities were actively exploited by threat actors, prompting the urgent need for patching.
The affected MacOS versions are Ventura 13.4.1, Monterey 12.6.7, and Big Sur 11.7.8. The exploit code is designed to download additional components, acquiring root privileges on the targeted device. Subsequently, a backdoor is deployed in memory, and the initial iMessage is erased to hide any traces of the infection. These activities encompass interacting with the device's file system (such as creating, modifying, exfiltrating, and deleting files), managing processes (listing and terminating them), extracting keychain items to gather victim credentials, and monitoring the victim's geolocation, among other actions.
Apple has also addressed a third zero-day vulnerability, identified as CVE-2023-32439, which was reported anonymously. This flaw could potentially lead to arbitrary code execution when handling malicious web content. Apple has resolved the actively exploited flaw, characterized as a type confusion problem, by implementing enhanced checks.
Recommendations:
We strongly recommend you update the following products to the given version.
References:
The following reports contain further technical details:
https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html
[/emaillocker]