News: 1634054530

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple patches 'actively exploited' iPhone zero-day with iOS 15.0.2 update

(2021/10/12)


If you're using an iPhone, install the iOS 15.0.2 update immediately: Apple has warned that the latest OS upgrade patches an "actively exploited" zero-day.

Described as a "memory corruption issue" by Apple, the vuln is present within the IOMobileFrameBuffer kernel extension, used for managing display memory. Malicious applications are said to be capable of triggering an integer overflow in the framebuffer, permitting execution of arbitrary code with kernel privileges.

The bug, publicly tracked as CVE-2021-30883, has not yet been published in full although technical descriptions and proofs of concept are already circulating on security-focused areas of the web.

[1]

While Apple stuck to its customarily terse and detail-free description of the vuln on its patch notes page, the world has been heavily focused on an iPhone-specific malware strain – Pegasus, one of [2]Israeli malware vendor NSO Group's flagship products . Pegasus is the tip of the iceberg, as NCSC chief exec Lindy Cameron [3]mentioned yesterday in a major speech .

[4]

[5]

Reverse engineer and exploit mitigator Saar Amar published a technical analysis and [6]proof-of-concept exploit shortly after Apple pushed the update, noting that the exploitable function "is accessible directly from the app sandbox" by iOS apps, with no special user-account privileges required.

Precise details of how Pegasus infects iPhones isn't available in public, though it is understood that the malware was previously known to be [7]capable of spreading without user interaction – "no-click install" is the phrase preferred by NSO. Previous methods that may have been used include an exploit of a now-patched WhatsApp zero day that allowed attackers to infect a mark by making [8]booby-trapped WhatsApp calls to the victim's iPhone or Android handset – calls they didn't even have to answer.

[9]

Pegasus malware is sold to nation states for surveillance purposes and can harvest user data and log information from a host of commonly used apps. It has been widely used to spy on human rights activists whose activities might embarrass rulers of authoritarian countries.

[10]Apple patches zero-day vulnerability in iOS, iPadOS, macOS under active attack

[11]Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait

[12]Apple warns of arbitrary code execution zero-day being actively exploited on Macs

[13]Update Firefox: Mozilla just patched three hijack-me holes and a bunch of other flaws

Jake Moore, a cybersecurity specialist with antivirus firm ESET, commented: "Kernel-level access is about the most severe vulnerability you can get which means this is no ordinary patch and must be attended to as soon as possible. Criminal hackers will continue to attack any given weakness which is why automating security updates remains the safest way of keeping devices up to date."

The flaw is quite similar to one patched in July, [14]which also existed in IOMobileFrameBuffer and which Amar also [15]said he had come across, though formal attribution was to an anonymous researcher. ®

Get our [16]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWYFnza6al6w-Dc40Jo0WAAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2021/10/07/pegasus_malware_princess_haya/

[3] https://www.theregister.com/2021/10/11/ncsc_ceo_speech_chatham_house/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnza6al6w-Dc40Jo0WAAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWYFnza6al6w-Dc40Jo0WAAAAIk&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://saaramar.github.io/IOMFB_integer_overflow_poc/

[7] https://www.theregister.com/2019/05/14/whatsapp_zero_day/

[8] https://www.theregister.com/2019/05/14/whatsapp_zero_day/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWYFnza6al6w-Dc40Jo0WAAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/07/27/apple_patches_zeroday/

[11] https://www.theregister.com/2021/09/24/apple_zeroday/

[12] https://www.theregister.com/2021/09/24/apple_zero_day/

[13] https://www.theregister.com/2020/06/04/firefox_77_security_fixes/

[14] https://www.theregister.com/2021/07/27/apple_patches_zeroday/

[15] https://twitter.com/AmarSaar/status/1419770084780875779

[16] https://whitepapers.theregister.com/



If it is similar to the last one

DS999

Either the previous fix was incomplete or this was the next vulnerability NSO group had ready in case their previous one was found and fixed.

If Apple was clever they'd pay a few government lackeys somewhere in the world who are in a position to purchase NSO group's services to do so for a few phones in Apple's labs. Provide them with appropriately spoofed GPS info, etc. and simulate normal usage while logging all traffic and waiting for NSO group's next exploit to be put into service. With all the logging to know exactly how the exploit works they could knock them down as quickly as NSO group could put them up until they run out.

What to do?

HildyJ

When somebody left the walled garden's gate open?

On a more serious note, it's too bad Apple can't get info from the NSA who developed many of the tools the NSO uses. Unfortunately, Western intelligence agencies want the tools for themselves. But, of course, they'd never use them for evil.

...and now we spin the roulette wheel...

Omnipresent

Is it a necessary update? or a data stealing forced hardware buy?

And will it keep my icloud pics off the web? Come one, Come all....

oh yeah, we announced a new apple event with new hardware at the same time if you didn't hear. Your guess is as good as mine.

Real computer scientists only write specs for languages that might run
on future hardware. Nobody trusts them to write specs for anything homo
sapiens will ever be able to fit on a single planet.