News: 1611693931

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple emits emergency iOS security updates while warning holes may have been exploited in wild by hackers

(2021/01/26)


Apple today released software updates to patch vulnerabilities in iPhones and iPads that may have been exploited by miscreants to silently snoop on victims from afar.

Folks should check for and install the latest version of their iOS, iPadOS, watchOS, and tvOS software. Here's the quick run down of the programming blunders:

[1]

CVE-2021-1782: Fixed in [2]iOS 14.4 and iPadOS 14.4 , available for iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation). This kernel-level race condition can be exploited by malicious code on a device – such as a rogue or hijacked app – to gain control of the iThing. Apple said it is "aware of a report that this issue may have been actively exploited." How would one inject malicious code into a device? Look no further than...

CVE-2021-1871, CVE-2021-1870: Also fixed in iOS 14.4 and iPadOS 14.4, a logic bug in WebKit that can be exploited by a malicious webpage – opened in, say, Safari – to execute arbitrary code. Again, Apple is aware this may have been exploited in the wild.

[3]

Presumably someone chained these bugs with the above one to take control of someone's handheld after tricking them visit a bobby-trapped website. The page would inject an execute a payload in Safari, which which would then use the kernel vulnerability to gain the necessary privileges to commandeer the equipment, spy on its owner, snoop on communications, and so on.

The CVE-2021-1782 flaw is also fixed in [4]tvOS 14.4 , available for Apple TV 4K and Apple TV HD models, and [5]watchOS 7.3 , available for the Apple Watch Series 3 and later. All three bugs were reported to Apple privately by an anonymous researcher.

In addition to these fixes, Apple also emitted [6]Xcode 12.4 that fixes CVE-2021-1800 , a bug that can be exploited by malicious applications running on someone's Mac to access a user's personal files. It was reported by Theodore Dubois, and is not believed to have been exploited in the wild.

The iGiant also released [7]iCloud for Windows 12.0 to address:

CVE-2020-29611: Found by Ivan Fratric of Google Project Zero, this vulnerability can be exploited by a specially crafted image to achieve arbitrary code execution. That means you could send a picture to someone, and if it's opened by them using this software, malware hidden in the file could be allowed to run and get up to all sorts of mischief.

CVE-2020-29618: Found by Xingwei Lin of Ant Security Light-Year Lab, this works just like the above image-parsing hole, leading to code execution.

CVE-2020-29617, CVE-2020-29619: Xingwei Lin again, this time with bugs that can corrupt the heap, and presumably crash the application, via a maliciously crafted image.

None of the iCloud for Windows flaws are said to have been exploited in the wild.

The iOS and iPadOS patches come a day after Google revealed North Korea's hackers had [8]targeted information security researchers, luring them to a website that seemingly contained a Chrome zero-day exploit to infect their Windows PCs and offering them bobby-trapped Visual Studio project files.

[9]

A spokesperson for Apple was not immediately available to confirm whether or not today's software updates and yesterday's disclosure are linked. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YBCfBcR4AqVBIWZPWHVobwAAAEk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://support.apple.com/en-us/HT212146

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YBCfBcR4AqVBIWZPWHVobwAAAEk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://support.apple.com/en-us/HT212149

[5] https://support.apple.com/en-us/HT212148

[6] https://support.apple.com/en-us/HT212153

[7] https://support.apple.com/en-us/HT212145

[8] https://www.theregister.com/2021/01/26/north_korea_targeted_me_0_day/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YBCfBcR4AqVBIWZPWHVobwAAAEk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://whitepapers.theregister.com/

ExRLCBod

bobby trapped? who on earth is bobby and why is he trapped inside a VS project?

Anonymous Coward

No, bobby trapped is correct. Booby trapped The former term was determined to be sexist except when used to describe a breast mammary gland entrapped in a bra Under Garment-High(UGH).

... and now I'm out of here is fast as my little legs can carry me.

Space is big. You just won't believe how vastly, hugely, mind-bogglingly
big it is. I mean, you may think it's a long way down the road to the
drug store, but that's just peanuts to space.
-- The Hitchhiker's Guide to the Galaxy