No, it doesn’t just crash Safari. Apple has yet to fix exploitable flaw

No, it doesn’t just crash Safari. Apple has yet to fix exploitable flaw

Apple has yet to patch a security bug found in iPhones and Macs despite the availability of a fix released almost three weeks ago, a researcher said.

The vulnerability resides in WebKit, the browser engine that powers Safari and all browsers that run on iOS. When the vulnerability was fixed almost three weeks ago by open source developers outside of Apple, the fix’s release notes said that the bug caused Safari to crash. A researcher from security firm Theori said the flaw is exploitable, and despite the availability of a fix, the bug is still present in iOS and macOS.

Mind the gap

“This bug yet again demonstrates that patch-gapping is a significant danger with open source development,” Theori researcher Tim Becker wrote in a post published Tuesday. “Ideally, the window of time between a public patch and a stable release is as small as possible. In this case, a newly released version of iOS remains vulnerable weeks after the patch was public.”

“Patch-gapping” is the term used to describe the exploitation of a vulnerability during the usually brief window between the time it’s fixed upstream and when it becomes available to end-users. In an interview, Becker said that the patch has yet to make its way into macOS as well.

The vulnerability stems from what security researchers call a type confusion bug in the WebKit implementation of AudioWorklet, an interface that allows developers to control, manipulate, render, and output audio and decrease latency. Exploiting the vulnerability gives an attacker the basic building blocks to remotely execute malicious code on affected devices.

To make the exploitation work in real-world scenarios, however, an attacker would still need to bypass Pointer Authentication Codes, or PAC, an exploit mitigation system that requires a cryptographic signature before code in memory can be executed. Without the signature or a bypass, it would be impossible for malicious code written by the WebKit exploit to actually run.

“The exploit builds arbitrary read/write primitives which could be used as part of a larger exploit chain,” Becker said, referring to proof-of-concept attack code his company has released. “It does not bypass PAC. We consider PAC bypasses to be separate security issues and thus should be disclosed separately.”

Theori said that company researchers independently discovered the vulnerability but that it had been fixed upstream before they could report it to Apple.

“We didn’t expect Safari to still be vulnerable weeks after the patch was public, but here we are… ” Becker wrote on Twitter.

Eight Apple zero-days and counting

While the threat posed by this vulnerability isn’t immediate, it’s still potentially serious because it clears a significant hurdle required to wage the kinds of in-the-wild exploits that have bedeviled iOS and macOS users in recent months.

According to a spreadsheet maintained by Google’s Project Zero vulnerability research team, seven vulnerabilities have been actively exploited against Apple users since the beginning of the year. The figure rises to eight if you include a macOS zero-day that Apple patched on Monday. Six of the eight vulnerabilities resided in WebKit.

Apple representatives didn’t respond to an email seeking comment for this post.

https://arstechnica.com/?p=1767876




Vulnerability in VMware product has severity rating of 9.8 out of 10

Close-up photo of police-style caution tape stretched across an out-of-focus background.

Data centers around the world have a new concern to contend with—a remote code vulnerability in a widely used VMware product.

The security flaw, which VMware disclosed and patched on Tuesday, resides in the vCenter Server, a tool used for managing virtualization in large data centers. vCenter Server is used to administer VMware’s vSphere and ESXi host products, which by some rankings are the first and second most popular virtualization solutions on the market. Enlyft, a site that provides business intelligence, shows that more than 43,000 organizations use vSphere.

“Serious”

A VMware advisory said that vCenter machines using default configurations have a bug that, in many networks, allows for the execution of malicious code when the machines are reachable on a port that is exposed to the Internet. The vulnerability is tracked as CVE-2021-21985 and has a severity score of 9.8 out of 10.

“The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server,” Tuesday’s advisory stated. “VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8… A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.”

In response to the frequently asked question “When do I need to act?” company officials wrote, “Immediately, the ramifications of this vulnerability are serious.”

Independent researcher Kevin Beaumont agreed.

“vCenter is a virtualization management software,” he said in an interview. “If you hack it, you control the virtualization layer (e.g., VMware ESXi)—which allows access before the OS layer (and security controls). This is a serious vulnerability, so organizations should patch or restrict access to the vCenter server to authorized administrators.”

Shodan, a service that catalogs sites available on the Internet, shows that there are almost 5,600 public-facing vCenter machines. Most or all of those reside in large data centers potentially hosting terabytes of sensitive data. Shodan shows that the top users with vCenter servers exposed on the Internet are Amazon, Hetzner Online GmbH, OVH SAS, and Google.

CVE-2021-21985 is the second vCenter vulnerability this year to carry a 9.8 rating. Within a day of VMware patching the vulnerability in February, proof-of-concept exploits appeared from at least six different sources. The disclosure set off a frantic round of mass Internet scans as attackers and defenders alike searched for vulnerable servers.

vCenter versions 6.5, 6.7, and 7.0 are all affected. Organizations with vulnerable machines should prioritize this patch. Those who can’t install immediately should follow Beaumont’s workaround advice. VMware has more workaround guidance here.

VMware credited Ricter Z of 360 Noah Lab for reporting this issue.

https://arstechnica.com/?p=1767612




ICS Vendors Assessing Impact of New OPC UA Vulnerabilities

Multiple companies that develop industrial systems are assessing the impact of two new OPC UA vulnerabilities on their products, and German automation technology firm Beckhoff is the first to release a security advisory.

Earlier this month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released advisories to describe two OPC UA vulnerabilities discovered by Eran Jacob of OTORIO, an Israel-based company that specializes in operational technology (OT) security and digital risk management solutions.

Developed by the OPC Foundation, OPC UA (Unified Architecture) is a machine-to-machine communication protocol that is widely used in industrial automation and other fields.

Jacob, who is the security research team lead at OTORIO, analyzed OPC UA and uncovered a couple of vulnerabilities that have been assigned a high severity rating.New OPC UA vulnerabilities affect the products of ICS vendors

One of the flaws is tracked as CVE-2021-27432 and it has been described as an uncontrolled recursion issue that can be exploited to trigger a stack overflow. This vulnerability has been found to impact OPC UA .NET Standard and Legacy.

The second vulnerability is CVE-2021-27434, which has been described as a sensitive information disclosure issue that impacts the Unified Automation .NET based OPC UA client/server SDK.

The OPC Foundation released a patch in March. The flaw affecting Unified Automation software is related to the use of vulnerable versions of the .NET framework. According to CISA, CVE-2021-27434 is related to a .NET vulnerability patched by Microsoft in 2015 (CVE-2015-6096). CISA said Unified Automation has addressed the issue with an update.

Learn More About Vulnerabilities in Industrial Products at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits Virtual Event Series

Jacob told SecurityWeek that multiple vendors are assessing the potential impact of these vulnerabilities on their products — he has notified them through CISA — but it seems that so far only Beckhoff has released an advisory.

In the advisory, published on May 14, the company said components of its TwinCAT PLC runtime are impacted by the security holes.

Beckhoff, whose advisory was also published by Germany’s [email protected], said the vulnerabilities can be exploited by an unauthenticated attacker to cause a denial of service (DoS) condition or to obtain information by sending specially crafted OPC UA packets. The information disclosure issue was described by the company as an XML external entity (XXE) flaw.

“For both kinds of attacks the attacker needs to use a specifically crafted OPC UA client when attacking an OPC UA server, respectively needs to use a specifically crafted OPC UA server when attacking an OPC UA client,” Beckhoff explained. “For attacking a server the attacker needs to be able to establish a TCP connection to that server. For attacking a client the attacker needs to be able to make the client connect to the attacker’s server. For all cases it is sufficient if after the establishment of the TCP connection the attacker lets the specifically crafted application (client or server) respond with a sequence of specifically crafted network packets.”

Jacob said it’s possible to exploit the vulnerabilities remotely from the internet “if the vulnerable OPC UA server is accessible through the internet, or a vulnerable client accesses a server controlled by an attacker through the internet.”

“Theoretically, an attacker performing DoS to an OPC UA server may impact connectivity between control systems, which can result in loss of visibility and possibly loss of control on the process,” Jacob explained. “Also, theoretically, the XXE vulnerability may allow leaking of sensitive files from the system (for example – unprotected private keys or configuration files), or it can be used to perform arbitrary HTTP GET requests on behalf of the attacked server/client.”

Related: Industrial Firms Informed About Serious Vulnerabilities in Matrikon OPC Product

Related: Many Vulnerabilities Found in OPC UA Industrial Protocol

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/Po-TVFzP4hc/ics-vendors-assessing-impact-new-opc-ua-vulnerabilities




Microsoft Unveils SimuLand: Open Source Attack Techniques Simulator

Microsoft this week announced the availability of SimuLand, an open source tool that enables security researchers to reproduce attack techniques in lab environments.

The purpose of SimuLand, Microsoft says, is to help understand the behavior and functionality of threat actors’ tradecraft, to find mitigations and validate existing detection capabilities, and to identify and share data sources relevant to adversary detection.

SimuLand can be used to test the effectiveness of Microsoft 365 Defender, Azure Defender, and Azure Sentinel detections.

Furthermore, it is expected to help accelerate the building and deployment of threat research lab environments and to enable security researchers to stay up to date with the techniques and tools that threat actors employ in real-world attacks.

“Our goal is to have SimuLand integrated with threat research methodologies where dynamic analysis is applied to end-to-end simulation scenarios,” Microsoft says.

Based on open-source projects such as Azure Sentinel2Go and the Open Threat Research (OTR) community’s Blacksmith and featuring a modular design, SimuLand can be used to test various combinations of attack actions and also includes guides for lab deployment and for executing simulation exercises.

The simulator can replicate different types of environments (hybrid, cloud) and includes Azure Resource Manager (ARM) templates. The vast majority of the lab environments in the project require at least an Azure tenant and a Microsoft 365 E5 license (paid or trial).

The tool aims to get researchers accustomed with attacker behavior, and “every simulation plan provided through this project is research-based and broken down into attacker actions mapped to the MITRE ATT&CK framework,” Microsoft notes.

Moving forth, the tech company will focus on creating more scenarios, delivering a data model for a more organized documentation of simulation steps, developing capabilities to export generated telemetry and share it with the community, and more.

Related: Microsoft Open-Sources ‘CyberBattleSim’ Enterprise Environment Simulator

Related: Microsoft Releases Open Source Fuzzing Framework for Azure

Related: Microsoft Open-Sources COVID-19 Threat Intelligence

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/j0kUSLrYDmY/microsoft-unveils-simuland-open-source-attack-techniques-simulator




4 vulnerabilities under attack give hackers full control of Android devices

A computer screen filled with ones and zeros also contains a Google logo and the word hacked.

Unknown hackers have been exploiting four Android vulnerabilities that allow the execution of malicious code that can take complete control of devices, Google warned on Wednesday.

All four of the vulnerabilities were disclosed two weeks ago in Google’s Android Security Bulletin for May. Google has released security updates to device manufacturers, who are then responsible for distributing the patches to users.

Google’s May 3 bulletin initially didn’t report that any of the roughly 50 vulnerabilities it covered were under active exploitation. On Wednesday, Google updated the advisory to say that there are “indications” that four of the vulnerabilities “may be under limited, targeted exploitation.” Maddie Stone, a member of Google’s Project Zero exploit research group, removed the ambiguity. She declared on Twitter that the “4 vulns were exploited in-the-wild” as zero-days.

Complete control

Successful exploits of the vulnerabilities “would give complete control of the victim’s mobile endpoint,” Asaf Peleg, vice president of strategic projects for security firm Zimperium, said in an email. “From elevating privileges beyond what is available by default to executing code outside of the current process’s existing sandbox, the device would be fully compromised, and no data would be safe.”

So far, there have been four Android zero-day vulnerabilities disclosed this year, compared with one for all of 2020, according to figures from Zimperium.

Two of the vulnerabilities are in Qualcomm’s Snapdragon CPU, which powers the majority of Android devices in the US and a massive number of handsets overseas. CVE-2021-1905, as the first vulnerability is tracked, is a memory-corruption flaw that allows attackers to execute malicious code with unfettered root privileges. The vulnerability is classified as severe, with a rating of 7.8 out of 10.

The other vulnerability, CVE-2021-1906, is a logic flaw that can cause failures in allocating new GPU memory addresses. The severity rating is 5.5. Frequently, hackers chain two or more exploits together to bypass security protections. That is likely the case with the two Snapdragon flaws.

The other two vulnerabilities under attack reside in drivers that work with ARM graphics processors. Both CVE-2021-28663 and CVE-2021-28664 are also memory-corruption flaws that allow attackers to gain root access on vulnerable devices.

No actionable advice from Google

There are no other details about the in-the-wild attacks. Google representatives didn’t respond to emails asking how users can tell if they’ve been targeted.

The skill required to exploit the vulnerabilities has led some researchers to speculate that the attacks are likely the work of nation-state-backed hackers.

“The complexity of this mobile attack vector is not unheard of but is outside the capabilities of an attacker with rudimentary or even intermediate knowledge of mobile endpoint hacking,” Peleg said. “Any attacker using this vulnerability is most likely doing so as part of a larger campaign against an individual, enterprise, or government with the goal of stealing critical and private information.”

It’s not clear precisely how someone would go about exploiting the vulnerabilities. The attacker could send malicious text messages or trick targets into installing a malicious app or visiting a malicious website.

Without more actionable information from Google, it’s impossible to provide helpful advice to Android users except to say that they should ensure all updates have been installed. Those using Android devices from Google will automatically receive patches in the May security rollout. Users of other devices should check with the manufacturer.

https://arstechnica.com/?p=1766173




Apple reports 2 iOS 0-days that let hackers compromise fully patched devices

Five iPhones on a table
Enlarge / The 2020 iPhone lineup. From left to right: iPhone 12 Pro Max, iPhone 12 Pro, iPhone 12, iPhone SE, and iPhone 12 mini.

A week after Apple issued its biggest iOS and iPadOS update since last September’s release of version 14.0, the company has released a new update to patch two zero-days that allowed attackers to execute malicious code on fully up-to-date devices. Monday’s release of version 14.5.1 also fixes problems with a bug in the newly released App Tracking Transparency feature rolled out in the previous version.

Both vulnerabilities reside in Webkit, a browser engine that renders Web content in Safari, Mail, App Store, and other select apps running on iOS, macOS, and Linux. CVE-2021-30663 and CVE-2021-30665, as the zero-days are tracked, have now been patched. Last week, Apple fixed CVE-2021-30661, another code-execution flaw in iOS Webkit, that also might have been actively exploited.

“Processing maliciously crafted web content may lead to arbitrary code execution,” Apple said in its security notes, referring to the flaws. “Apple is aware of a report that this issue may have been actively exploited.” MacOS 11.3.1, which Apple also released on Monday, also fixed CVE-2021-30663 and CVE-2021-30665.

CVE-2021-30665 was discovered by researchers from China-based security firm Qihoo 360. The other vulnerability was discovered by an anonymous source. Apple provided no details about who is using the exploits or who is being targeted by them.

Coveted by black hats, feared by defenders

According to figures from Google’s Project Zero vulnerability research team, the three recently patched iOS vulnerabilities bring the number of zero-days actively exploited against iOS users to seven. With a total of 22 zero-days found so far in 2021, those exploiting the Apple mobile OS make up almost 33 percent of them. That makes iOS the second most targeted software by zero-days this year, behind Chrome, which has had eight zero-days.

Zero-days are highly coveted by black hats and feared by defenders because they are unknown to the developers of the vulnerable software and the public at large. That means the people who discover the security flaws can use them to hack devices that are fully up to date, often with little or no detection.

Separately, 14.5.1 fixes a bug that kept some users from seeing App Tracking Transparency prompts.

“This update fixes an issue with App Tracking Transparency where some users who previously disabled Allow Apps to Request to Track in Settings may not receive prompts from apps after re-enabling it,” the update description said. “This update also provides important security updates and is recommended for all users.”

Apple rolled out App Tracking Transparency in last week’s release of iOS 14.5. The addition has roiled Facebook because it prevents the company’s app from tracking user activity across other apps users have installed without explicit permission. A second bug can cause the App Tracking Transparency toggle in the settings menu to be grayed out. There are numerous reports that the toggle remains grayed out for many users even after updating to iOS 14.5.1. Apple representatives didn’t immediately respond to a request for comment.

https://arstechnica.com/?p=1762039




More US agencies potentially hacked, this time with Pulse Secure exploits

More US agencies potentially hacked, this time with Pulse Secure exploits
Getty Images

At least five US federal agencies may have experienced cyberattacks that targeted recently discovered security flaws that give hackers free rein over vulnerable networks, the US Cybersecurity and Infrastructure Security Agency said on Friday.

The vulnerabilities in Pulse Connect Secure, a VPN that employees use to remotely connect to large networks, include one that hackers had been actively exploiting before it was known to Ivanti, the maker of the product. The flaw, which Ivanti disclosed last week, carries a severity rating of 10 out of a possible 10. The authentication bypass vulnerability allows untrusted users to remotely execute malicious code on Pulse Secure hardware, and from there, to gain control of other parts of the network where it’s installed.

Federal agencies, critical infrastructure, and more

Security firm FireEye said in a report published on the same day as the Ivanti disclosure that hackers linked to China spent months exploiting the critical vulnerability to spy on US defense contractors and financial institutions around the world. Ivanti confirmed in a separate post that the zeroday vulnerability, tracked as CVE-2021-22893, was under active exploit.

In March, following the disclosure of several other vulnerabilities that have now been patched, Ivanti released the Pulse Secure Connect Integrity Tool, which streamlines the process of checking whether vulnerable Pulse Secure devices have been compromised. Following last week’s disclosure that CVE-2021-2021-22893 was under active exploit, CISA mandated that all federal agencies run the tool

“CISA is aware of at least five federal civilian agencies who have run the Pulse Connect Secure Integrity Tool and identified indications of potential unauthorized access,” Matt Hartman, deputy executive assistant director at CISA, wrote in an emailed statement. “We are working with each agency to validate whether an intrusion has occurred and will offer incident response support accordingly.”

CISA said it’s aware of compromises of federal agencies, critical infrastructure entities, and private sector organizations dating back to June 2020.

They just keep coming

The targeting of the five agencies is the latest in a string of large-scale cyberattacks to hit sensitive government and business organizations in recent months. In December, researchers uncovered an operation that infected the software build and distribution system of network management tools maker SolarWinds. The hackers used their control to push backdoored updates to about 18,000 customers. Nine government agencies and fewer than 100 private organizations—including Microsoft, antivirus maker Malwarebytes, and Mimecast—received follow-on attacks.
In March, hackers exploiting newly discovered vulnerability in Microsoft Exchange compromised an estimated 30,000 Exchange servers in the US and as many as 100,000 worldwide.
Microsoft said that Hafnium, its name for a group operating in China, was behind the attacks. In the days that followed, hackers not affiliated by Hafnium began infecting the already-compromised servers to install a new strain of ransomware.
Two other serious breaches have also occurred, one against the maker of the Codecov software developer tool and the other against the seller of Passwordstate, a password manager used by large organizations to store credentials for firewalls, VPNs, and other network-connected devices. Both breaches are serious, because the hackers can use them to compromise the large number of customers of the companies’ products.

Ivanti said it’s helping to investigate and respond to exploits, which the company said have been “discovered on a very limited number of customer systems.”

“The Pulse team took swift action to provide mitigations directly to the limited number of impacted customers that remediates the risk to their system, and we plan to issue a software update within the next few days,” a spokesperson added.

https://arstechnica.com/?p=1761727




Vulnerability Exposes F5 BIG-IP to Kerberos KDC Hijacking Attacks

F5 Networks this week released patches to address an authentication bypass vulnerability affecting BIG-IP Access Policy Manager (APM), but fixes are not available for all impacted versions.

Tracked as CVE-2021-23008, the high-severity vulnerability allows for the bypass of BIG-IP APM AD (Active Directory) authentication if the attacker can hijack a Kerberos KDC (Key Distribution Center) connection using a spoofed AS-REP (Kerberos Authentication Service Response).

Authentication bypass is also possible from an AD server that the attacker has already compromised, F5 explains. The attacker could also bypass policies and gain unfettered access to sensitive workloads, according to identity protection firm Silverfort, whose researchers discovered the vulnerability.

“In some cases this can be used to bypass authentication to the Big-IP admin console as well,” the researchers say.

The Kerberos protocol leverages a client-server model for on-premise authentication, with KDC being an intermediary that holds shared secret keys and user access information. When attempting to access a resource, the KDC prompts for a username and password and also checks if the user has privileges to access that resource.

For the protocol to work, the user and the KDS authenticate to the server and the server authenticates to the client. If the Kerberos KDC authentication to the server is compromised, the attacker can hijack the connection between the client and the domain controller, thus bypassing authentication.

Such attacks typically exploit misconfigurations in Kerberos protocol implementations, and the same applies to F5 BIG-IP as well. Thus, an attacker can create a domain controller with a username identical to the admin’s username and target the flaw to authenticate to BIG-IP even if they do not know the correct password, by hijacking the KDC connection.

“For an APM access policy configured with AD authentication and SSO (single sign-on) agent, if a spoofed credential related to this vulnerability is used, depending how the back-end system validates the authentication token it receives, access will most likely fail. An APM access policy can also be configured for BIG-IP system authentication. A spoofed credential related to this vulnerability for an administrative user through the APM access policy results in local administrative access,” F5 notes.

BIG-IP APM versions 11.5.2 through 16.0.1 are known to be vulnerable. Fixes were included in BIG-IP APM versions 12.1.6, 13.1.4, 14.1.4, and 15.1.3, but no patches are available for the 11.x and 16.x branches.

As for mitigations, F5, which also credits Thierry Van Steirteghem from Exclusive Networks for reporting the vulnerability, suggests enabling multi-factor authentication (MFA), or host-level authentication.

This week, the company also released patches for a medium-severity vulnerability in BIG-IP APM (CVE-2021-23016) that could be abused to bypass internal restrictions and retrieve static content stored within APM.

Related: Researchers Raise Alarm for F5 BIG-IP Malware Attacks

Related: F5 Patches Four Critical Bugs in Big-IP Suite

Related: Vulnerability Exposes F5 BIG-IP Systems to Remote DoS Attacks

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/86VYA9DFkjQ/vulnerability-exposes-f5-big-ip-kerberos-kdc-hijacking-attacks




DigitalOcean Discloses Breach Involving Billing Information

Cloud solutions provider DigitalOcean has started informing some customers that their billing information may have been compromised after someone exploited a vulnerability in the company’s systems.

In an email sent to customers, DigitalOcean said the unauthorized access occurred between April 9 and April 22, 2021, but it was apparently only “confirmed” on April 26.

“An unauthorized user gained access to some of your billing account details through a flaw that has been fixed,” the company told customers.

DigitalOcean said only a “small percentage” of its customers were impacted and they do not need to take any action.

The exposed billing information includes name, address, payment card expiration date, the payment card’s last four digits, and the name of the bank that issued the card. The company highlighted that it does not store full credit card data so this type of information was not exposed.

“According to our logs approximately 1% of billing profiles were impacted,” Tyler Healy, VP of security at DigitalOcean, told SecurityWeek in an emailed statement. “This issue has been fixed and we have informed the impacted users and notified the relevant data protection authorities.”

On its website, DigitalOcean says more than one million developers from every country in the world use its services.

The company informed customers last year that it had exposed some of their data after a document was unintentionally made public, but claimed at the time it was confident that there was no malicious access to the document.

Related: Ubiquiti Tells Users to Change Passwords After Breach at Cloud Provider

Related: Cloud(y) with a Chance of a Data Breach

Related: DigitalOcean Warns of Vulnerability Affecting Cloud Users

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/ChohrSXNhAY/digitalocean-discloses-breach-involving-billing-information




Apple Patches Security Bypass Vulnerability Impacting Macs With M1 Chip

Apple’s latest macOS updates patch three vulnerabilities that can be exploited to bypass security mechanisms, including one that has been exploited in the wild and one that impacts only Macs powered by the M1 chip.

It was reported earlier this week that one of the security holes patched in macOS Big Sur and Catalina (CVE-2021–30657) has been exploited by a piece of malware known as Shlayer to bypass security mechanisms designed by Apple to protect users against malicious files downloaded from the internet, specifically file quarantine, Gatekeeper and notarization.

File quarantine asks the user for confirmation when executing a file downloaded from the internet, Gatekeeper checks code-signing information to ensure an application comes from a trusted developer and it has not been tampered with, and notarization involves automatically scanning software for malicious content before it is allowed to run.

CVE-2021–30657 is related to script-based applications that do not contain an “Info.plist” configuration file being misclassified. The issue was detailed this week by Cedric Owens, the researcher who discovered the bug, Apple security expert Patrick Wardle, who described its root cause and developed a PoC exploit, and Apple device management company Jamf, whose researchers discovered that the Shlayer malware had been exploiting the vulnerability since at least January 2021.

Two other similar vulnerabilities have been patched by Apple with the release of the latest macOS updates: one discovered by Wojciech Reguła of SecuRing (CVE-2021-30658) and one by Rasmus Sten of F-Secure (CVE-2021-1810). However, these do not appear to have been exploited in malicious attacks.

Reguła told SecurityWeek that the vulnerability he found can only be triggered on Macs with the M1 chip. He will likely publish a blog post detailing his findings, but he has shared some high-level information about the flaw, which only impacts macOS Big Sur.

“[The vulnerability] abuses the ‘/System/Library/CoreServices/Applications/iOS App Installer.app’ system application that will install an iOS App (with .ipa extension) on M1 Macs,” the researcher explained.

In a PoC video shared with SecurityWeek, Reguła showed that an attacker needs to trick the targeted user into clicking on a link and installing an application, but no security prompts related to Gatekeeper are displayed before the malicious .ipa application is executed. He said he also leveraged an additional trick to prevent the operating system from assigning it the file quarantine attribute.

Gatekeeper bypass vulnerability

F-Secure published a blog post with a brief explanation of Sten’s findings, but the company is not releasing any technical details just yet to prevent exploitation.

Sten told SecurityWeek that the vulnerability he discovered is similar to the one that has been exploited in the wild — it can bypass all three security features — but it uses different mechanisms to achieve the same goal. This issue affects the Archive Utility component in macOS Big Sur and Catalina.

The flaw involves specially crafted ZIP archive files that the targeted user needs to download, unpack and execute in order to trigger the exploit. This results in the application contained in the ZIP file — it can be a piece of malware — getting executed without any warning to the user.

However, F-Secure noted in its blog post that applications downloaded from the official App Store are not impacted and apps delivered as macOS installer packages cannot exploit the vulnerability as they contain a certificate that is verified outside of Gatekeeper.

“The most likely scenario is a phishing attack or a web server compromise, where an attacker is able to serve a legitimate-looking web page masquerading as a legitimate software vendor,” Sten explained. “This can then be used to trick the user into downloading a malicious app masquerading as a legitimate app. By exploiting CVE-2021-1810 this app would be able to run when the user double-clicks on it despite the fact that it hasn’t been signed or notarised.”

A short video demo of the vulnerability in action was posted by Sten on Twitter.

Related: Researchers Show First Side-Channel Attack Against Apple M1 Chips

Related: Mac Malware ‘XCSSET’ Adapted for Devices With M1 Chips

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

http://feedproxy.google.com/~r/Securityweek/~3/x-Pli6ip98g/apple-patches-security-bypass-vulnerability-impacting-macs-m1-chip