News: 1694172971

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple races to patch the latest zero-day iPhone exploit

(2023/09/08)


Apple devices are again under attack, with a zero-click, zero-day vulnerability used to deliver Pegasus spyware to iPhones discovered in the wild.

Even running the latest version of iOS (16.6) is no defence against the exploit, which involves PassKit attachments containing malicious images. Once sent to the victim's iMessage account, the NSO Group's Pegasus spyware can be deployed without interaction.

Researchers at Citizen Lab are referring to the exploit as [1]BLASTPASS . The team said they immediately disclosed their findings to Apple when they first discovered an infected device owned by an individual employed by a Washington DC-based civil society organization with international offices.

[2]

Apple moved swiftly, assigning two CVEs to the exploit chain – CVE-2023-41064 and CVE-2023-41061 – and issuing updates for iOS and iPadOS. Apple and Citizen Lab also advised enabling Lockdown Mode, which blocks the attack, for at-risk users.

[3]

[4]

Citizen Lab said: "We commend Apple for their rapid investigative response and patch cycle, and we acknowledge the victim and their organization for their collaboration and assistance."

While Citizen Lab did not immediately respond to a request for more detail regarding the exploit chain – and the org plans an updated post on this topic in the future – some information can be gleaned from [5]Apple's release notes .

[6]

CVE-2023-41064 is related to a buffer overflow issue in ImageIO where processing a maliciously crafted image might result in arbitrary code execution. The same result was noted for Wallet in CVE-2023-41061 due to a maliciously crafted attachment. In the latter's case, Apple dealt with a validation issue with improved logic.

PassKit is the service for distributable passes added to a user's Apple wallet. A pass is a signed Bundle containing a JSON description, images and localizations.

[7]China reportedly bans iPhones from more government offices

[8]Barracuda gateway attacks: How Chinese snoops keep a grip on victims' networks

[9]US Cyber Command boss says China's spooky cyber skills still behind

[10]Prepare for plenty more pain from Ivanti's MDM flaws, warn cyber agencies

Pegasus is the infamous spyware its developer, Israel's [11]NSO Group , claims is only sold to legitimate government agencies. Once installed, it can monitor calls and messages and use the phone's camera. Despite [12]protestations that the spyware is only licensed to government agencies to thwart criminals, its use has [13]generated alarm among lawmakers and privacy activists alike.

In 2020 and 2021, Citizen Lab [14]found the malware lurking on devices throughout the UK government.

As for the latest exploits, the advice is to update your iOS and iPadOS devices immediately. Unless, of course, [15]you work for the Chinese government . ®

Get our [16]Tech Resources



[1] https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPtFJNjH2hWds0bXTWfMSgAAAYg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPtFJNjH2hWds0bXTWfMSgAAAYg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPtFJNjH2hWds0bXTWfMSgAAAYg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://support.apple.com/en-us/HT213905

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPtFJNjH2hWds0bXTWfMSgAAAYg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/09/07/china_government_reportedly_bans_iphones/

[8] https://www.theregister.com/2023/08/30/mandiant_barracuda_esg_bug/

[9] https://www.theregister.com/2023/08/11/nsa_boss_says_chinas_hackers/

[10] https://www.theregister.com/2023/08/03/ivanti_cisa_norway_attack/

[11] https://www.theregister.com/2023/05/30/nso_owner_hacking/

[12] https://www.nsogroup.com/Newses/the-facts-about-nso/

[13] https://www.theregister.com/2022/07/27/us_congress_spyware_debate/

[14] https://citizenlab.ca/2022/04/uk-government-officials-targeted-pegasus/

[15] https://www.theregister.com/2023/09/07/china_government_reportedly_bans_iphones/

[16] https://whitepapers.theregister.com/



This was patched yesterday

ferkle

Not to be that guy, but 16.6.1 released yesterday has patched this vuln out.

Re: This was patched yesterday

Annihilator

Not to be that other guy...

"Apple moved swiftly, assigning two CVEs to the exploit chain – CVE-2023-41064 and CVE-2023-41061 – and issuing updates for iOS and iPadOS"

"As for the latest exploits, the advice is to update your iOS and iPadOS devices immediately"

And despite all that, it was a zero-day exploit discovered in the wild. So still newsworthy, and a prompt reminder to patch. Despite having auto-updates on, mine hadn't done it yet - just done it manually.

Re: This was patched yesterday

pluraquanta

I've had lockdown mode enabled for about two months. I haven't noticed any reduction in functionality, except people I don't know can't call me on Facetime.

Grunchy

What?

Guys, get real: the insecurity is the iMessage service itself !

Any information you send via Apple or Google or Microsoft is definitely getting read by artificially intelligent daemons trying to figure out how to steal your money or your vote or your stock tips or whatever else they can steal.

It has always been the policy that format conversions go in user space.
The kernel is an arbitrator of resources it is not a shit bucket for
solving other peoples incompetence.

- Alan Cox on linux-kernel