Apple Patches Actively Exploited Zero-Day in Its Ecosystem

Apple has recently rolled out a series of updates for its operating systems and Safari browser, addressing several vulnerabilities that were actively being exploited by unknown threat actors. Among these vulnerabilities are two zero-days that have been used in a surveillance campaign called Operation Triangulation since 2019.

The first vulnerability, CVE-2023-32434, is an integer overflow flaw in the Kernel that could be exploited by a malicious app to execute arbitrary code with kernel privileges. The second vulnerability, CVE-2023-32435, is a memory corruption issue in WebKit that could result in arbitrary code execution when processing specially crafted web content.

Apple has acknowledged that these two vulnerabilities may have been actively exploited on iOS versions released prior to iOS 15.7. In their analysis, the researchers discovered a spyware implant known as TriangleDB, which was delivered through zero-click attacks via iMessages containing an exploit for a remote code execution vulnerability.

Spyware Resides Solely in Memory

The implant operates exclusively in memory, making it difficult to detect, and it has various capabilities for data collection and tracking, including file system interaction, process management, keychain item extraction for gathering credentials, and geolocation monitoring.

In addition to the zero-days, Apple has also patched another vulnerability, CVE-2023-32439, which could lead to arbitrary code execution when processing malicious web content. The update is available for various platforms, including iOS, iPadOS, macOS, watchOS, and Safari.

These latest fixes bring the total number of zero-day vulnerabilities addressed by Apple this year to nine. In previous updates, Apple resolved other vulnerabilities, such as a WebKit flaw (CVE-2023-23529) that allowed remote code execution and two bugs (CVE-2023-28205 and CVE-2023-28206) that enabled code execution with elevated privileges.

June 22, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.