HomeTechApple rushes to fix zero-day flaws exploited by Pegasus spyware on iPhones

Apple rushes to fix zero-day flaws exploited by Pegasus spyware on iPhones

September 08, 2023THNSpyware/vulnerability

Apple on Thursday released emergency security updates for iOS, iPadOS, macOS and watchOS to address two zero-day flaws that have been exploited in the wild to deliver NSO Group solutions. Pegasus mercenary spyware.

The problems are described below:

  • CVE-2023-41061 – A validation issue in Wallet that could result in arbitrary code execution when handling a maliciously crafted attachment.
  • CVE-2023-41064 – A buffer overflow problem in the Image I/O component this could result in arbitrary code execution when processing a maliciously crafted image.

While CVE-2023-41064 was found by the Citizen Lab at the University of Toronto Munk School, CVE-2023-41061 was discovered internally by Apple, with “assistance” from Citizen Lab.

cyber security

Updates are available for the following devices and operating systems:

In a separate alert, Citizen Lab revealed that the twin flaws have been weaponized as part of a chain of clickless iMessage exploits called BLASTPASS to deploy Pegasus on iPhones fully patched with iOS 16.6.

“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” the interdisciplinary lab saying. “The exploit involved PassKit attachments containing malicious images sent from an attacker’s iMessage account to the victim.”

Additional technical details about shortcomings have been hidden in light of active exploitation. That being said, the exploit is said to prevent BlastDoor Testing Framework created by Apple to mitigate clickless attacks.

“This latest finding once again shows that civil society is the target of highly sophisticated exploits and mercenary spyware,” Citizen Lab said, adding that the problems were found last week while examining the device of an unidentified individual employed by an organization. of civil society based in Washington DC. with international offices.

NEXT WEBINAR

Too Vulnerable: Discovering the State of the Identity Attack Surface

Did you get the MFA? PAM? Service account protection? Find out how well equipped your organization really is against identity threats

Boost your skills

Cupertino has so far fixed a total of 13 zero-day bugs in its software since the beginning of the year. The latest updates also come more than a month after the company shipped fixes for an actively exploited kernel flaw (CVE-2023-38606).

The zero-day news comes as the Chinese government is believed to have tidy to prohibition ban central and state government officials from using iPhones and other foreign-branded devices for work in a bid to reduce reliance on foreign technology and amid an escalating trade war between China and the United States.

“The real reason (for the ban) is: cybersecurity (surprise surprise),” said Zuk Avraham, security researcher and founder of Zimperium. saying in a post on X (formerly Twitter). “iPhones have the image of being the most secure phone… but in reality, iPhones are not at all secure against simple eavesdropping.”

“Don’t you believe me? Just look at the number of commercial 0-click companies like NSOs over the years to understand that there is almost nothing an individual, organization, or government can do to protect themselves against cyber-espionage through of iPhones.”.

Did you find this article interesting? follow us Twitter and LinkedIn to read more exclusive content that we publish.



Source link


Discover more from PressNewsAgency

Subscribe to get the latest posts sent to your email.

- Advertisment -