Maddie Stone

Pesquisador deGoogleâs Threat Analysis Group
#2907de 53,638
87CVSS total
Vulnerabilidades · 10
Média
1
Alta
8
Crítica
1
PT-2023-5473
7.8
2023-09-06
Apple · Ipados · CVE-2023-41992
**Name of the Vulnerable Software and Affected Versions** Apple macOS versions prior to 12.7 Apple iOS versions prior to 16.7 Apple iPadOS versions prior to 16.7 Apple watchOS versions prior to 9.6.3 Apple macOS Ventura versions prior to 13.6 Apple watchOS versions prior to 10.0.1 Apple iPadOS versions prior to 17.0.1 Apple iOS versions prior to 17.0.1 **Description** The issue involves insufficient checks when processing web content within the kernel of iOS, watchOS, iPadOS, and macOS, potentially allowing an attacker to elevate their privileges. Reports indicate that this issue may have been actively exploited in versions of iOS prior to iOS 16.7. The vulnerability allows malicious applications to bypass signature validation and gain elevated privileges. The issue was addressed by implementing improved checks. The vulnerability affects multiple Apple platforms. Technical details reveal the exploitation involves triggering a bug on an old thread, invoking `ipc entry grow table()` through `mach port allocate name()`, and subsequently calling `mach thread self()` to obtain a new mach name. **Recommendations** Update macOS to version 12.7 or later. Update iOS to version 16.7 or later. Update iPadOS to version 16.7 or later. Update watchOS to version 9.6.3 or later. Update macOS Ventura to version 13.6 or later. Update watchOS to version 10.0.1 or later. Update iPadOS to version 17.0.1 or later. Update iOS to version 17.0.1 or later.
PT-2023-5474
10
2023-07-18
Apple · Ios · CVE-2023-41993
**Name of the Vulnerable Software and Affected Versions** Apple Safari versions prior to 16.6.1 Apple macOS versions prior to Ventura 13.6 Apple iOS versions prior to 16.7 Apple iPadOS versions prior to 16.7 Apple macOS Sonoma versions prior to 14 webkit2gtk versions prior to 2.42.1 Oracle Java SE version 8u401 Oracle GraalVM Enterprise Edition versions 20.3.13 and 21.3.9 **Description** A vulnerability exists in the WebKit engine, potentially allowing attackers to execute arbitrary code by processing malicious web content. This issue has been actively exploited in some instances, with reports indicating exploitation against iOS versions prior to 16.7. The vulnerability was addressed through improved checks in updated versions of the software. A threat actor, linked to Russia’s Foreign Intelligence Service (SVR), leveraged this vulnerability (CVE-2023-41993) in a watering hole campaign, compromising legitimate websites and redirecting visitors to malicious login pages to harvest Microsoft 365 credentials. Intellexa, a spyware vendor, also utilized this vulnerability as part of a zero-day exploit chain to deploy the Predator spyware on targets in Egypt. The exploit chain involved multiple zero-day vulnerabilities, including CVE-2023-41993, to gain deep access to devices. **Recommendations** Update Apple Safari to version 16.6.1 or later. Update Apple macOS to version Ventura 13.6 or later, or macOS Sonoma 14 or later. Update Apple iOS to version 16.7 or later. Update Apple iPadOS to version 16.7 or later. Update webkit2gtk to version 2.42.1 or later. Update Oracle Java SE to a version after 8u401. Update Oracle GraalVM Enterprise Edition to a version after 20.3.13 and 21.3.9.