CVE-2019-8605
published 2019-12-18CVE-2019-8605: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A…
PriorityP182high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-07-18
Exploited in the wild
EPSS
17.44%
96.8th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios | >= unspecified < iOS 12.3 | iOS 12.3 |
| apple | iphone_os | < 12.3 | 12.3 |
| apple | mac_os_x | < 10.14.5 | 10.14.5 |
| apple | macos | >= unspecified < macOS Mojave 10.14.5 | macOS Mojave 10.14.5 |
| apple | macos_mojave_10.14.6_supplemental_update | — | — |
| apple | tvos | < 12.3 | 12.3 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < tvOS 12.3 | tvOS 12.3 |
| apple | watchos | < 5.2.1 | 5.2.1 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < watchOS 5.2.1 | watchOS 5.2.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The CVE-2019-8605 (SockPuppet) exploit is reachable from the iOS app sandbox via TCP sockets using IPV6_3542PKTINFO (option 46) on AF_INET6/SOCK_STREAM sockets followed by disconnectx() and getsockopt() — monitor for this syscall sequence from sandboxed apps. ↗
- →The Operation Poisoned News campaign delivered the CVE-2019-8605 kernel exploit via hidden iframes on watering-hole websites. Detect hidden iframe injection on news/forum pages targeting iOS Safari user-agents. ↗
- →Kernel panic backtrace for CVE-2019-8605 crash shows _in6_selectsrc + 0x114 → _nd6_setdefaultiface + 0xd75 → _soconnectlock + 0x284. Use this call chain to identify crash dumps related to exploitation attempts. ↗
- →lightSpy malware modules (ios_wechat, ios_qq, ios_telegram, KeyChain, FileManage, ShellCommandaaa, Locationaaa, WifiList, browser, Screenaaa, SoftInfoaaa) should be hunted as unexpected dylib files or processes on jailbroken iOS devices. ↗
- ·The original raw-socket PoC (exploit-db 46892) requires root privileges; however, the TCP-based reproducer is reachable from the iOS app sandbox, making it significantly more dangerous for real-world exploitation. ↗
- ·The Operation Poisoned News exploit chain targets iOS 12.1 and 12.2 specifically, using a silently patched Safari bug (no CVE) chained with CVE-2019-8605 for kernel privilege escalation. Devices on iOS 12.3+ (except 12.4) are not vulnerable to this specific chain. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple Multiple Products Use-After-Free Vulnerability
cisa·2022-06-27·CVSS 7.8
CVE-2019-8605 [HIGH] CWE-416 Apple Multiple Products Use-After-Free Vulnerability
Vulnerability: Apple Multiple Products Use-After-Free Vulnerability
Affected: Apple Multiple Products
A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-8605
Remediation Due Date: 2022-07-18
Apple
CVE-2019-8605: tvOS 12.4.1
vendor_apple·2019-08-26·CVSS 7.8
CVE-2019-8605 [HIGH] CVE-2019-8605: tvOS 12.4.1
Apple Security Update: About the security content of tvOS 12.4.1
Product: tvOS
Version: 12.4.1
CVE: CVE-2019-8605
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2019-8605: macOS Mojave 10.14.6 Supplemental Update
vendor_apple·2019-08-26·CVSS 7.8
CVE-2019-8605 [HIGH] CVE-2019-8605: macOS Mojave 10.14.6 Supplemental Update
Apple Security Update: About the security content of macOS Mojave 10.14.6 Supplemental Update
Product: macOS Mojave 10.14.6 Supplemental Update
CVE: CVE-2019-8605
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2019-8605: iOS 12.4.1
vendor_apple·2019-08-26·CVSS 7.8
CVE-2019-8605 [HIGH] CVE-2019-8605: iOS 12.4.1
Apple Security Update: About the security content of iOS 12.4.1
Product: iOS
Version: 12.4.1
CVE: CVE-2019-8605
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A use after free issue was addressed with improved memory management.
Apple
CVE-2019-8605: watchOS 5.2.1
vendor_apple·2019-05-13·CVSS 7.8
CVE-2019-8605 [HIGH] CVE-2019-8605: watchOS 5.2.1
Apple Security Update: About the security content of watchOS 5.2.1
Product: watchOS
Version: 5.2.1
CVE: CVE-2019-8605
Component: Kernel
Impact: A malicious application may be able to execute arbitrary code with system privileges
Description: A use after free issue was addressed with improved memory management.
GHSA
GHSA-rv43-fj24-7hpc: A use after free issue was addressed with improved memory management
ghsa_unreviewed·2022-05-24
CVE-2019-8605 [HIGH] CWE-416 GHSA-rv43-fj24-7hpc: A use after free issue was addressed with improved memory management
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges.
Project0
Designing sockfuzzer, a network syscall fuzzer for XNU - Project Zero
project_zero·2021-04-01·CVSS 7.8
CVE-2019-8605 [HIGH] Designing sockfuzzer, a network syscall fuzzer for XNU - Project Zero
Posted by Ned Williamson, Project Zero
Introduction
When I started my 20% project – an initiative where employees are allocated twenty-percent of their paid work time to pursue personal projects – with Project Zero, I wanted to see if I could apply the techniques I had learned fuzzing Chrome to XNU, the kernel used in iOS and macOS. My interest was sparked after learning some prominent members of the iOS research community believed the kernel was “fuzzed to death,” and my understanding was that most of the top researchers used auditing for vulnerability research. This meant finding new bugs with fuzzing would be meaningful in demonstrating the value of implementing newer fuzzing techniques. In this project, I pursued a somewhat unusual approach to fuzz XNU networking in userland by con
Project0
A survey of recent iOS kernel exploits - Project Zero
project_zero·2020-06-01
CVE-2016-7644 A survey of recent iOS kernel exploits - Project Zero
Posted by Brandon Azad, Project Zero
I recently found myself wishing for a single online reference providing a brief summary of the high-level exploit flow of every public iOS kernel exploit in recent years; since no such document existed, I decided to create it here.
This post summarizes original iOS kernel exploits from local app context targeting iOS 10 through iOS 13, focusing on the high-level exploit flow from the initial primitive granted by the vulnerability to kernel read/write. At the end of this post, we will briefly look at iOS kernel exploit mitigations (in both hardware and software) and how they map onto the techniques used in the exploits.
This isn't your typical P0 blog post: There is no gripping zero-day exploitation, or novel exploitation research, or thrilling mal
Project0
Remote iPhone Exploitation Part 3: From Memory Corruption to JavaScript and Back -- Gaining Code Execution - Project Zero
project_zero·2020-01-01
CVE-2019-8605 Remote iPhone Exploitation Part 3: From Memory Corruption to JavaScript and Back -- Gaining Code Execution - Project Zero
Posted by Samuel Groß, Project Zero
This is the third and last post in a series about a remote, interactionless iPhone exploit over iMessage. The first blog post introduced the exploited vulnerability, and the second blog post described a way to perform a heapspray, leaking the shared cache base address.
At this point, ASLR has been broken as the shared cache’s base address is known and controlled data can be placed at a known address with the heap spray. What remains is to exploit the vulnerability one more time to gain code execution.
After a short introduction to some relevant ObjC internals, an exploit for devices without pointer authentication (PAC) will be outlined. It involves creating code pointers, so it no longer works with pointer authentication enabled. Afterwards, a diff
Project0
SockPuppet: A Walkthrough of a Kernel Exploit for iOS 12.4 - Project Zero
project_zero·2019-12-01·CVSS 7.8
CVE-2019-8605 [HIGH] SockPuppet: A Walkthrough of a Kernel Exploit for iOS 12.4 - Project Zero
Posted by Ned Williamson, 20% on Project Zero
Introduction
I have a somewhat unique opportunity in this writeup to highlight my experience as an iOS research newcomer. Many high quality iOS kernel exploitation writeups have been published, but those often feature weaker initial primitives combined with lots of cleverness, so it’s hard to tell which iOS internals were specific to the exploit and which are generic techniques.
In this post, we’ll look at CVE-2019-8605, a vulnerability in the iOS kernel and macOS for five years and how to exploit it to achieve arbitrary kernel read/write. This issue affected XNU as early as 2013, and was reported by me to Apple on March 2019. It was then patched in iOS 12.3 in May 2019 and I released the complete details including the exploit for iOS for
VulnCheck
Apple Multiple Products Use-After-Free Vulnerability
vulncheck·2019·CVSS 7.8
CVE-2019-8605 [HIGH] CWE-416 Apple Multiple Products Use-After-Free Vulnerability
Apple Multiple Products Use-After-Free Vulnerability
A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
Affected: Apple Multiple Products
Required Action: Apply updates per vendor instructions.
Exploitation References: https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/05dcb535155a; https://vulncheck.com/xdb/e1003c53cc92
Remediation Due: 2022-07-18
No detection rules found.
Exploit-DB
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
exploitdb·2019-09-23·CVSS 7.8
CVE-2019-8605 [HIGH] iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
---
Exploit Title: SockPuppet 3
Date: September 8, 2019
Exploit Author: Umang Raghuvanshi
Vendor Homepage: https://apple.com
Software Link: https://ipsw.me/
Version: iOS 11.0—12.2, iOS 12.4
Tested on: iOS 11.0—12.2, iOS 12.4
CVE: CVE-2019-8605
This is an alternative (and complete) exploit for CVE-2019-8605. I have only implemented the exploit and do not claim any rights for discovering and/or publishing the vulnerability. The actual exploit code is in “SockPuppet3.cpp”, other files are either helpers or documentation. This exploit [1] has already been verified in production several times [2] [3], however, I can assist in additional verification if required.
POC:
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/b
Exploit-DB
Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
exploitdb·2019-05-21
CVE-2019-8605 Apple macOS < 10.14.5 / iOS < 12.3 XNU - 'in6_pcbdetach' Stale Pointer Use-After-Free
Apple macOS so_flags & SOF_PCBCLEARING)) {
struct ip_moptions *imo;
struct ip6_moptions *im6o;
inp->inp_vflag = 0;
if (inp->in6p_options != NULL) {
m_freem(inp->in6p_options);
inp->in6p_options = NULL; // in6p_outputopts); // in6p_route);
// free IPv4 related resources in case of mapped addr
if (inp->inp_options != NULL) {
(void) m_free(inp->inp_options); // inp_options = NULL;
}
```
Notice that freed options must also be cleared so they are not accidentally reused.
This can happen when a socket is disconnected and reconnected without being destroyed.
In the inp->in6p_outputopts case, the options are freed but not cleared, so they can be
used after they are freed.
This specific PoC requires root because I use raw sockets, but it's possible other socket
types suffer from this same vulner
arXiv
PTAuth: Temporal Memory Safety via Robust Points-to Authentication
arxiv_fulltext·2020-10-26
PTAuth: Temporal Memory Safety via Robust Points-to Authentication
: Temporal Memory Safety via Robust Points-to Authentication
Reza Mirzazade Farkhani
Northeastern University
[email protected]
Mansour Ahmadi
Northeastern University
[email protected]
Long Lu
Northeastern University
[email protected]
gobble
page1
## Abstract
Temporal memory corruptions are commonly exploited software vulnerabilities that
can lead to powerful attacks. Despite significant progress made by decades of
research on mitigation techniques, existing countermeasures fall short due to
either limited coverage or overly high overhead. Furthermore, they require
external mechanisms (e.g., spatial memory safety) to protect their metadata.
Otherwise, their protection can be bypassed or disabled.
To address these limitations, we present robust points-to
Trendmicro
Op Poisoned News Targets Hong Kong Users with Malware in Mobile News Links
blogs_trendmicro·2020-03-24
Op Poisoned News Targets Hong Kong Users with Malware in Mobile News Links
Mobile
# Op Poisoned News Targets Hong Kong Users with Malware in Mobile News Links
A recently discovered watering hole attack has been targeting iOS users in Hong Kong. The campaign uses links posted on multiple forums that supposedly lead to various news stories. While these links lead users to the actual news sites, they also use a hidden iframe to load and execute malicious code.
By: Elliot Cao, Joseph C Chen, William Gamazo Sanchez, Lilang Wu, Ecular Xu
2020/03/24
Read time: ( words)
Save to Folio
A recently discovered watering hole attack has been targeting iOS users in Hong Kong. The campaign uses links posted on multiple forums that supposedly lead to various news stories. While these links lead users to the actual news sites, they also use a hidden iframe to load and execute
Tenable
Apple iPhone and iPad Devices Vulnerable After Reintroduction of SockPuppet Flaw in iOS 12.4 (CVE-2019-8605)
blogs_tenable·2019-08-20·CVSS 7.8
[HIGH] Apple iPhone and iPad Devices Vulnerable After Reintroduction of SockPuppet Flaw in iOS 12.4 (CVE-2019-8605)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://support.apple.com/HT210118https://support.apple.com/HT210119https://support.apple.com/HT210120https://support.apple.com/HT210122https://support.apple.com/HT210118https://support.apple.com/HT210119https://support.apple.com/HT210120https://support.apple.com/HT210122https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8605
2019-12-18
Published
2022-06-27
Added to CISA KEV
Exploited in the wild