News: 1632459668

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple warns of arbitrary code execution zero-day being actively exploited on Macs

(2021/09/24)


Apple has warned iPhone and Mac users that it's aware of a zero-day bug that's being actively exploited.

The iGiant has thanked Google for spotting CVE-2021-30869, which the ad giant seems to have noticed because it also impacts the WebKit browser engine.

It's a nasty flaw, as it's in the XNU kernel at the heart of Apple's operating systems including macOS and iOS.

[1]

As Apple's [2]advisory explains, that means "A malicious application may be able to execute arbitrary code with kernel privileges".

[3]

[4]

The fruit-themed company says the flaw existed thanks to a "type confusion issue" that was sorted out "with improved state handling".

The kicker: "Apple is aware of reports that an exploit for this issue exists in the wild."

[5]

The fix is Security Update 2021-006 Catalina, which Macs should be urging you about as you read this article – making this the rare occasion on which it might be best to put down The Register and move on to another task.

0day privilege escalation for macOS Catalina discovered in the wild by [6]@eryeh [7]https://t.co/yvCWPo45fL

We saw this used in conjunction with a N-day remote code execution targeting WebKit.

Thanks to Apple for getting patch out so quickly. — Shane Huntley (@ShaneHuntley) [8]September 23, 2021

The flaw's also present in older versions of iOS, and impacts the iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad Mini 2, iPad Mini 3, and iPod Touch.

[9]Apple, Google yank opposition voting strategy app from Russian software stores

[10]One-size-fits-all chargers? What a great idea! Of course Apple would hate it, though

[11]Apple's M1 MacBook screens are stunning – stunningly fragile and defective, that is, lawsuits allege

The fix is iOS 12.5.5, which Apple's [12]advisory points out also addresses arbitrary code execution flaws in WebKit and CoreGraphics.

You know the drill, people. And while you're letting Apple's machines patch themselves up, consider that the company appears not to have fixed a [13]similar remote code execution flaw in the macOS Finder, despite third-party researchers trying to fix it. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://support.apple.com/en-us/HT212825

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://twitter.com/eryeh?ref_src=twsrc%5Etfw

[7] https://t.co/yvCWPo45fL

[8] https://twitter.com/ShaneHuntley/status/1441102086385455112?ref_src=twsrc%5Etfw

[9] https://www.theregister.com/2021/09/18/google_apple_votng_app_russia/

[10] https://www.theregister.com/2021/09/23/eu_one_charger_plan/

[11] https://www.theregister.com/2021/09/16/apple_m1_macbook_screen_lawsuits/

[12] https://support.apple.com/en-us/HT212824

[13] https://www.theregister.com/2021/09/22/macos_rce_flaw/

[14] https://whitepapers.theregister.com/



Ever touch my iPod Classic

Anonymous Coward

And there will be BIG trouble!

Having these 0 days is definitely not a good thing

DS999

But on the bright side Apple is continuing to support its stuff far longer than the competition. This iOS 12 update now makes a full EIGHT YEARS of support for the iPhone 5S, and counting.

Feels a bit click-baity

GordonD

to build a story from a release note for an update to an older OS version, and not call that out.

MacOS usage by version is hard to come by, but I'm sure Simon knows that Catalina is not the most recent, soon to be current - 2, and probably represents less than 25% of active MacOS installations; so one has to wonder why this most pertinent of facts was not highlighted.

Similarly, as noted in previous comments, iOS 12 is far from recent, so this story should mention that iOS 12 and earlier represents maybe 7% of the installed base.

Last paragraph missing?

pavel.petrman

You know, the one about asking Apple for comment. I always read the last paragraph about Apple. A rare source of rock solid stability in these turbulent times.

Would ye both eat your cake and have your cake?
-- John Heywood