Security

Patches

Apple squashes iOS, macOS zero-day bugs already exploited by snoops

Keep calm and install patches before abuse becomes widespread


Apple rolled out patches on Good Friday to its iOS, iPadOS, and macOS operating systems and the Safari web browser to address vulnerabilities found by Google and Amnesty International that were exploited in the wild.

The fixes released on April 7 squash two security bugs – CVE-2023-28205 and CVE-2023-28206 – in Apple WebKit and IOSurfaceAcclerator, respectively. Snoops who successfully exploit both holes can execute arbitrary code with kernel privileges, enabling them to pretty much run any command or code they wish on the compromised device. That would allow them to steal data and spy on targets. All a victim would have to do is open some kind of maliciously crafted webpage on a vulnerable device.

The updates are to iOS 16.4.1, iPadOS 16.4.1, Safari 16.4.1, and macOS 13.3.1. Apple released iOS 16.4 and macOS 13.3 March 27.

The updates are available for a range of devices, from the iPhone 8 and later, all models of the iPad Pro, third-generation iPad Airs and later, and iPad and iPad Mini tablets that are fifth generation and later. If this seems familiar to you, in February Cupertino patched similar flaws in its operating systems.

Apple credited researchers Clément Lecigne of Google's Threat Analysis Group (TAG) and Donncha Ó Cearbhaill of Amnesty International's Security Lab with finding and reporting these latest holes.

Separate from the above, these fixes come after Google TAG and Amnesty International released reports on March 29 about two campaigns in which iOS and Android users had spyware slipped on their devices by some crew or other.

Amnesty's Security Lab late last year alerted Google to one of those campaigns – an effort by a "mercenary spyware company" to infect Android gear – leading to Google, Samsung, and other vendors releasing security updates that protected both Android and Linux users. Meanwhile, TAG detailed a campaign exploiting zero-days in both Android and iOS.

Amnesty didn't name the malware maker in its write-up, but said the infections indicated the "advanced spyware campaign" was "developed by a commercial cyber-surveillance company and sold to governments hackers to carry out targeted spyware attacks." The campaign has been active since at least 2020.

"While it is vital such vulnerabilities are fixed, this is merely a sticking plaster to a global spyware crisis," Cearbhaill said in a statement.

Amnesty International has called for a global moratorium on the development and sale of spyware, noting the high-profile abuses of the Pegasus spyware created by the NSO Group.

President Joe Biden in late March issued an executive order about the US government using such spyware, though it fell short of completely banning it. ®

Send us news
1 Comment

Goldman sacked: Apple 'wants out' of credit card collab

Don't be too shocked: Financial giant has been fleeing normie banking lately after failing to find footing

The 15-inch MacBook Air just nails it

Vast battery life, zippy performance, and rich speakers make an impressive package

A year on, CISA realizes debunked vuln actually a dud and removes it from must-patch list

Apparently no one thought to check if this D-Link router 'issue' was actually exploitable

US senator claims Google and Apple reveal push notification data to foreign govs

Cupertino promises to reveal its data deliveries, ending silence on the matter

Apple slaps patch on WebKit holes in iPhones and Macs amid fears of active attacks

Two CVEs can be abused to steal sensitive info or execute code

Steve Jobs' $4.01 RadioShack check set to fetch small fortune at auction

Talk about inflation – bids are now closing in on $30K

Two years on, 1 in 4 apps still vulnerable to Log4Shell

Lack of awareness still blamed for patching apathy despite it being among most infamous bugs of all time

UEFI flaws allow bootkits to pwn potentially hundreds of devices using images

Exploits bypass most secure boot solutions from the biggest chip vendors

OpenCart owner turns air blue after researcher discloses serious vuln

Web storefront maker fixed the flaw, but not before blasting infoseccer

Microsoft's bug bounty turns 10. Are these kinds of rewards making code more secure?

Katie Moussouris, who pioneered Redmond's program, says folks are focusing on the wrong thing

Apple's quest for modem independence from Qualcomm is going nowhere fast

iPhones could still be running Snapdragons into 2026

What do Apple, Meta, TikTok have in common? Fighting off Europe's stiff antitrust rules

Gatekeeper status under DMA? Don't you know who I am?