Apple warns of arbitrary code execution zero-day being actively exploited on Macs
- Reference: 1632459668
- News link: https://www.theregister.co.uk/2021/09/24/apple_zero_day/
- Source link:
The iGiant has thanked Google for spotting CVE-2021-30869, which the ad giant seems to have noticed because it also impacts the WebKit browser engine.
It's a nasty flaw, as it's in the XNU kernel at the heart of Apple's operating systems including macOS and iOS.
[1]
As Apple's [2]advisory explains, that means "A malicious application may be able to execute arbitrary code with kernel privileges".
[3]
[4]
The fruit-themed company says the flaw existed thanks to a "type confusion issue" that was sorted out "with improved state handling".
The kicker: "Apple is aware of reports that an exploit for this issue exists in the wild."
[5]
The fix is Security Update 2021-006 Catalina, which Macs should be urging you about as you read this article – making this the rare occasion on which it might be best to put down The Register and move on to another task.
0day privilege escalation for macOS Catalina discovered in the wild by [6]@eryeh [7]https://t.co/yvCWPo45fL
We saw this used in conjunction with a N-day remote code execution targeting WebKit.
Thanks to Apple for getting patch out so quickly. — Shane Huntley (@ShaneHuntley) [8]September 23, 2021
The flaw's also present in older versions of iOS, and impacts the iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad Mini 2, iPad Mini 3, and iPod Touch.
[9]Apple, Google yank opposition voting strategy app from Russian software stores
[10]One-size-fits-all chargers? What a great idea! Of course Apple would hate it, though
[11]Apple's M1 MacBook screens are stunning – stunningly fragile and defective, that is, lawsuits allege
The fix is iOS 12.5.5, which Apple's [12]advisory points out also addresses arbitrary code execution flaws in WebKit and CoreGraphics.
You know the drill, people. And while you're letting Apple's machines patch themselves up, consider that the company appears not to have fixed a [13]similar remote code execution flaw in the macOS Finder, despite third-party researchers trying to fix it. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://support.apple.com/en-us/HT212825
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YU2h1Lg001OpQYpKI0BzTQAAAMs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://twitter.com/eryeh?ref_src=twsrc%5Etfw
[7] https://t.co/yvCWPo45fL
[8] https://twitter.com/ShaneHuntley/status/1441102086385455112?ref_src=twsrc%5Etfw
[9] https://www.theregister.com/2021/09/18/google_apple_votng_app_russia/
[10] https://www.theregister.com/2021/09/23/eu_one_charger_plan/
[11] https://www.theregister.com/2021/09/16/apple_m1_macbook_screen_lawsuits/
[12] https://support.apple.com/en-us/HT212824
[13] https://www.theregister.com/2021/09/22/macos_rce_flaw/
[14] https://whitepapers.theregister.com/
Having these 0 days is definitely not a good thing
But on the bright side Apple is continuing to support its stuff far longer than the competition. This iOS 12 update now makes a full EIGHT YEARS of support for the iPhone 5S, and counting.
Feels a bit click-baity
to build a story from a release note for an update to an older OS version, and not call that out.
MacOS usage by version is hard to come by, but I'm sure Simon knows that Catalina is not the most recent, soon to be current - 2, and probably represents less than 25% of active MacOS installations; so one has to wonder why this most pertinent of facts was not highlighted.
Similarly, as noted in previous comments, iOS 12 is far from recent, so this story should mention that iOS 12 and earlier represents maybe 7% of the installed base.
Last paragraph missing?
You know, the one about asking Apple for comment. I always read the last paragraph about Apple. A rare source of rock solid stability in these turbulent times.
Ever touch my iPod Classic
And there will be BIG trouble!