CVE-2023-37450
published 2023-07-27CVE-2023-37450: The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6…
PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-08-03
Exploited in the wild
EPSS
18.95%
97.0th percentile
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.7.8_and_ipados | — | — |
| apple | ios_16.6_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 16.6 | 16.6 |
| apple | ipados | < 16.6 | 16.6 |
| apple | iphone_os | < 16.6 | 16.6 |
| apple | macos | >= 13.0 < 13.5 | 13.5 |
| apple | macos | >= unspecified < 13.5 | 13.5 |
| apple | macos_ventura | — | — |
| apple | rapid_security_responses_for_ios_16.5.1_and_ipados | — | — |
| apple | rapid_security_responses_for_macos_ventura | — | — |
| apple | safari | < 16.5.2 | 16.5.2 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 16.5 | 16.5 |
| apple | tvos | < 16.6 | 16.6 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < 16.6 | 16.6 |
| apple | watchos | < 9.6 | 9.6 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 9.6 | 9.6 |
| debian | webkit2gtk | < webkit2gtk 2.40.3-2~deb12u2 (bookworm) | webkit2gtk 2.40.3-2~deb12u2 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.40.3-2~deb12u2 (bookworm) | webkit2gtk 2.40.3-2~deb12u2 (bookworm) |
| webkitgtk | webkitgtk | < 2.42.3 | 2.42.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2023-37450 can be triggered by a vulnerable browser processing specially crafted web content, leading to arbitrary code execution via the WebKit engine ↗
- →The vulnerability resides in the WebKit browser engine used by Safari and other web browsers on iOS, iPadOS, and macOS; any browser processing untrusted web content on affected Apple platforms is an attack surface ↗
- →CVE-2023-37450 is confirmed actively exploited in the wild as a zero-day; prioritize detection of exploitation attempts against unpatched Apple WebKit-based browsers ↗
- →Apple's emergency patch (Rapid Security Response) for CVE-2023-37450 was initially released July 11 for iPhones and iPads; systems still running pre-patch versions of iOS 16.6, iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, or watchOS 9.6 should be flagged as vulnerable ↗
- →The WebKit component is the affected component; monitor for anomalous web content processing behavior or crashes in WebKit-based processes (e.g., com.apple.WebKit.WebContent) on Apple devices ↗
- ·Very few technical details about the exploit mechanism have been publicly disclosed; no specific IOCs (hashes, IPs, domains, URLs) have been attributed to exploitation of CVE-2023-37450 in the reviewed sources ↗
- ·Apple's initial Rapid Security Response patch caused Safari connectivity issues with major websites (Facebook, Instagram, Zoom) and was pulled back before a reliable fix was re-released; detection/patching pipelines should confirm the final fix version is applied, not the rolled-back RSR ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-37450: The issue was addressed with improved checks
osv·2023-07-27·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
GHSA
GHSA-v874-wp44-mhr4: The issue was addressed with improved checks
ghsa_unreviewed·2023-07-27
CVE-2023-37450 [HIGH] GHSA-v874-wp44-mhr4: The issue was addressed with improved checks
The issue was addressed with improved checks. This issue is fixed in watchOS 9.6, iOS 16.6 and iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
VulnCheck
Apple Multiple Products WebKit Code Execution Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-37450 [HIGH] Apple Multiple Products WebKit Code Execution Vulnerability
Apple Multiple Products WebKit Code Execution Vulnerability
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple Multiple Products
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/kb/HT213826; https://support.apple.com/kb/HT213823; https://support.apple.com/kb/HT213825; https://www.cisa.gov/site
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2023-07-31
CVE-2023-32393 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Apple
CVE-2023-37450: watchOS 9.6
vendor_apple·2023-07-24·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: watchOS 9.6
Apple Security Update: About the security content of watchOS 9.6
Product: watchOS
Version: 9.6
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Apple
CVE-2023-37450: iOS 16.6 and iPadOS 16.6
vendor_apple·2023-07-24·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: iOS 16.6 and iPadOS 16.6
Apple Security Update: About the security content of iOS 16.6 and iPadOS 16.6
Product: iOS 16.6 and iPadOS
Version: 16.6
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Apple
CVE-2023-37450: macOS Ventura 13.5
vendor_apple·2023-07-24·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: macOS Ventura 13.5
Apple Security Update: About the security content of macOS Ventura 13.5
Product: macOS Ventura
Version: 13.5
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Apple
CVE-2023-37450: tvOS 16.6
vendor_apple·2023-07-24·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: tvOS 16.6
Apple Security Update: About the security content of tvOS 16.6
Product: tvOS
Version: 16.6
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Apple
CVE-2023-37450: iOS 15.7.8 and iPadOS 15.7.8
vendor_apple·2023-07-24·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: iOS 15.7.8 and iPadOS 15.7.8
Apple Security Update: About the security content of iOS 15.7.8 and iPadOS 15.7.8
Product: iOS 15.7.8 and iPadOS
Version: 15.7.8
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Red Hat
webkitgtk: arbitrary code execution
vendor_redhat·2023-07-13·CVSS 8.8
CVE-2023-37450 [HIGH] CWE-94 webkitgtk: arbitrary code execution
webkitgtk: arbitrary code execution
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A vulnerability was found in webkitgtk. This issue occurs when processing web content, which may lead to arbitrary code execution.
Mitigation: This vulnerability can be mitigated by setting the environment variable JSC_useWebAssembly=0, which will disable support for WebAssembly. It's not necessary to set this environment variable if you're already using JavaScriptCoreUseJIT=0 to mitigate other CVEs because WebAssembly depends on JIT.
Package: webkitgtk (Red Hat E
CISA
Apple Multiple Products WebKit Code Execution Vulnerability
cisa·2023-07-13·CVSS 8.8
CVE-2023-37450 [HIGH] Apple Multiple Products WebKit Code Execution Vulnerability
Vulnerability: Apple Multiple Products WebKit Code Execution Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Notes: https://support.apple.com/en-us/HT213826, https://support.apple.com/en-us/HT213841, https://support.apple.com/en-us/HT213843, https://support.apple.com/en-us/HT213846, https://support.apple.com/en-us/HT213848; https://nvd.nist.gov/vuln/
Apple
CVE-2023-37450: Rapid Security Responses for macOS Ventura 13.4.1
vendor_apple·2023-07-10·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: Rapid Security Responses for macOS Ventura 13.4.1
Apple Security Update: About the security content of Rapid Security Responses for macOS Ventura 13.4.1
Product: Rapid Security Responses for macOS Ventura
Version: 13.4.1
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Apple
CVE-2023-37450: Rapid Security Responses for iOS 16.5.1 and iPadOS 16.5.1
vendor_apple·2023-07-10·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: Rapid Security Responses for iOS 16.5.1 and iPadOS 16.5.1
Apple Security Update: About the security content of Rapid Security Responses for iOS 16.5.1 and iPadOS 16.5.1
Product: Rapid Security Responses for iOS 16.5.1 and iPadOS
Version: 16.5.1
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Apple
CVE-2023-37450: Safari 16.5.2
vendor_apple·2023-07-10·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: Safari 16.5.2
Apple Security Update: About the security content of Safari 16.5.2
Product: Safari
Version: 16.5.2
CVE: CVE-2023-37450
Component: WebKit
Impact: Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Description: The issue was addressed with improved checks.
Debian
CVE-2023-37450: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in iOS 16.6 an...
vendor_debian·2023·CVSS 8.8
CVE-2023-37450 [HIGH] CVE-2023-37450: webkit2gtk - The issue was addressed with improved checks. This issue is fixed in iOS 16.6 an...
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Scope: local
bookworm: resolved (fixed in 2.40.3-2~deb12u2)
bullseye: resolved (fixed in 2.40.3-2~deb11u2)
forky: resolved (fixed in 2.40.4-1)
sid: resolved (fixed in 2.40.4-1)
trixie: resolved (fixed in 2.40.4-1)
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
blogs_bleepingcomputer·2025-03-11·CVSS 7.8
CVE-2025-24201 [HIGH] Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Sergiu Gatlan
Apple said attackers can exploit the CVE-2025-24201 vulnerability using maliciously crafted web content to break out of the Web Content sandbox.
The company has fixed this out-of-bounds write issue with improved checks to prevent unauthorized actions in iOS 18.3.2, iPadOS 18.3.2 , macOS Sequoia 15.3.2 , visionOS 2.3.2 , and Safari 18.3.1 .
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Macs
Bleepingcomputer
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
blogs_bleepingcomputer·2025-02-10·CVSS 7.8
[HIGH] Apple fixes zero-day exploited in 'extremely sophisticated' attacks
## Apple fixes zero-day exploited in 'extremely sophisticated' attacks
## Sergiu Gatlan
USB Restricted Mode is a security feature ( introduced almost seven years ago in iOS 11.4.1) that blocks USB accessories from creating a data connection if the device has been locked for over an hour. This feature is designed to block forensic software like Graykey and Cellebrite (commonly used by law enforcement) from extracting data from locked iOS devices.
In November, Apple introduced another security feature (dubbed "inactivity reboot") that automatically restarts iPhones after long idle times to re-encrypt data and make it harder to extract by forensic software.
The zero-day vulnerability (tracked as CVE-2025-24200 and reported by Citizen Lab's Bill Marczak) patched today by Apple is an author
Bleepingcomputer
Apple fixes this year’s first actively exploited zero-day bug
blogs_bleepingcomputer·2025-01-27·CVSS 6.5
CVE-2024-23222 [MEDIUM] Apple fixes this year’s first actively exploited zero-day bug
## Apple fixes this year’s first actively exploited zero-day bug
## Sergiu Gatlan
According to the company's official documentation , Core Media "defines the media pipeline used by AVFoundation and other high-level media frameworks found on Apple platforms."
Apple has fixed CVE-2024-23222 with improved memory management in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3.
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
macOS Sequoia
Apple Watch Ser
Bleepingcomputer
Apple fixes two zero-days used in attacks on Intel-based Macs
blogs_bleepingcomputer·2024-11-19·CVSS 8.8
CVE-2024-44308 [HIGH] Apple fixes two zero-days used in attacks on Intel-based Macs
## Apple fixes two zero-days used in attacks on Intel-based Macs
## Lawrence Abrams
The JavaScriptCore CVE-2024-44308 flaw allows attackers to achieve remote code execution through maliciously crafted web content. The other flaw, CVE-2024-44309, allows cross-site scripting (CSS) attacks.
The company says it addressed the security flaws in macOS Sequoia 15.1.1 .
As the same components are found in other Apple operating systems, it was also fixed in iOS 17.7.2 and iPadOS 17.7.2 , iOS 18.1.1 and iPadOS 18.1.1 , and visionOS 2.1.1 .
While Apple says both flaws were discovered by Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group, the company has not provided further details on how they were exploited.
BleepingComputer contacted Google to learn how the flaws were exploite
Bleepingcomputer
Apple fixes first zero-day bug exploited in attacks this year
blogs_bleepingcomputer·2024-01-22·CVSS 8.8
[HIGH] Apple fixes first zero-day bug exploited in attacks this year
## Apple fixes first zero-day bug exploited in attacks this year
## Sergiu Gatlan
"Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited," Apple said today.
The company has yet to attribute the discovery of this security vulnerability to a security researcher. Although the company disclosed that it's aware of in-the-wild exploitation, it has yet to publish further details regarding these attacks.
Apple addressed CVE-2024-23222 with improved checks in iOS 16.7.5 and later, iPadOS 16.7.5 and later, and macOS Monterey 12.7.3 and higher, as well as on tvOS 17.3 and later.
The complete list of devices impacted by this WebKit zero-day is quite extensive, as the bug affects older and newer models, i
Sentinelone
Protecting macOS | 7 Strategies for Enterprise Security in 2024
blogs_sentinelone·2024-01-02
Protecting macOS | 7 Strategies for Enterprise Security in 2024
Welcome to 2024! It may be a new year for us all, but it’s very much business as usual for cybersecurity professionals. Last year saw an increase in the number and variety of new threats targeting the macOS platform, and as the influence of the Mac continues to expand in enterprise environments, there is little doubt that 2024 will continue that trend.
In this post, we reflect on the lessons we can learn from the last 12 months of threat activity against Apple’s desktop operating system, and offer 7 strategies for defenders to help bolster their threat hunting, detection and mitigation efforts .
## 1. Don’t Rely on Persistence for Detection
Perhaps the most important lesson that defenders learned from 2023’s crop of macOS malware was that monitoring for persistence methods became a much
Sentinelone
Protecting macOS | 7 Strategies for Enterprise Security in 2024
blogs_sentinelone·2024-01-02
Protecting macOS | 7 Strategies for Enterprise Security in 2024
Welcome to 2024! It may be a new year for us all, but it’s very much business as usual for cybersecurity professionals. Last year saw an increase in the number and variety of new threats targeting the macOS platform, and as the influence of the Mac continues to expand in enterprise environments, there is little doubt that 2024 will continue that trend.
In this post, we reflect on the lessons we can learn from the last 12 months of threat activity against Apple’s desktop operating system, and offer 7 strategies for defenders to help bolster their threat hunting, detection and mitigation efforts.
## 1. Don’t Rely on Persistence for Detection
Perhaps the most important lesson that defenders learned from 2023’s crop of macOS malware was that monitoring for persistence methods became a much
Bleepingcomputer
Apple emergency updates fix recent zero-days on older iPhones
blogs_bleepingcomputer·2023-12-11·CVSS 6.5
[MEDIUM] Apple emergency updates fix recent zero-days on older iPhones
## Apple emergency updates fix recent zero-days on older iPhones
## Sergiu Gatlan
They can let attackers obtain access to sensitive data through and execute arbitrary code using maliciously crafted webpages designed to exploit out-of-bounds and memory corruption bugs on unpatched devices.
Today, Apple addressed the zero-days in iOS 16.7.3, iPadOS 16.7.3 , tvOS 17.2 , and watchOS 10.2 with improved input validation and locking.
The company says the bugs are now also patched on the following list of devices:
iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Apple TV HD and Apple TV 4K (all models)
Apple Watch Series 4 and later
Clément Lecigne, a security researcher from Google's Threat
Bleepingcomputer
Apple fixes two new iOS zero-days in emergency updates
blogs_bleepingcomputer·2023-11-30·CVSS 8.6
[HIGH] Apple fixes two new iOS zero-days in emergency updates
## Apple fixes two new iOS zero-days in emergency updates
## Sergiu Gatlan
The company says it addressed the security flaws for devices running iOS 17.1.2, iPadOS 17.1.2 , macOS Sonoma 14.1.2 , and Safari 17.1.2 with improved input validation and locking.
The list of impacted Apple devices is quite extensive, and it includes:
iPhone XS and later
iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Macs running macOS Monterey, Ventura, Sonoma
Security researcher Clément Lecigne of Google's Threat Analysis Group (TAG) found and reported both zero-days.
While Apple has not released information regarding ongoing exploitation in
Bleepingcomputer
Apple fixes iOS Kernel zero-day vulnerability on older iPhones
blogs_bleepingcomputer·2023-10-12·CVSS 7.8
CVE-2023-5217 [HIGH] Apple fixes iOS Kernel zero-day vulnerability on older iPhones
## Apple fixes iOS Kernel zero-day vulnerability on older iPhones
## Sergiu Gatlan
Apple has now also fixed the issue in iOS 16.7.1 and iPadOS 16.7.1 with improved checks, but it has yet to reveal who discovered and reported the flaw.
The second one, a bug identified as CVE-2023-5217, is caused by a heap buffer overflow vulnerability within the VP8 encoding of the open-source libvpx video codec library. This flaw could let threat actors gain arbitrary code execution upon successful exploitation.
Even though Apple did not confirm any instances of exploitation in the wild, Google previously patched the libvpx bug as a zero-day in its Chrome web browser. Microsoft also addressed the same vulnerability in its Edge, Teams, and Skype products.
Google attributed the discovery of CVE-2023-521
Bleepingcomputer
Apple emergency update fixes new zero-day used to hack iPhones
blogs_bleepingcomputer·2023-10-04·CVSS 7.8
[HIGH] Apple emergency update fixes new zero-day used to hack iPhones
## Apple emergency update fixes new zero-day used to hack iPhones
## Sergiu Gatlan
While Apple said it addressed the security issue in iOS 17.0.3 and iPadOS 17.0.3 with improved checks, it has yet to reveal who found and reported the flaw.
The list of impacted devices is quite extensive, and it includes:
iPhone XS and later
iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later
Apple also addressed a bug tracked as CVE-2023-5217 and caused by a heap buffer overflow weakness in the VP8 encoding of the open-source libvpx video codec library, which could allow arbitrary code execution following successful exploitation.
While Apple
Sentinelone
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
blogs_sentinelone·2023-10-03
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
This week, Firefox users were urged to apply Mozilla’s latest updates against a critical flaw that could allow attackers to take control of affected systems. It follows hard on the heels of similar updates for Microsoft Edge, Google Chrome, and Apple’s Safari browser. All have been heavily impacted by an actively exploited vulnerability in the WebP code library.
Although the WebP vulnerability affects other software as well, browsers are by far and away the most ubiquitous and widely used applications on end user devices . Having a foothold in a compromised browser gives threat actors access to sensitive information and potential avenues into targeted environments.
In this post, we take a deep dive into browser security , exploring the differences between vulnerabilities and exploits, ze
Sentinelone
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
blogs_sentinelone·2023-10-03
Beyond the WebP Flaw | An In-depth Look at 2023's Browser Security Challenges
This week, Firefox users were urged to apply Mozilla’s latest updates against a critical flaw that could allow attackers to take control of affected systems. It follows hard on the heels of similar updates for Microsoft Edge, Google Chrome, and Apple’s Safari browser. All have been heavily impacted by an actively exploited vulnerability in the WebP code library.
Although the WebP vulnerability affects other software as well, browsers are by far and away the most ubiquitous and widely used applications on end user devices. Having a foothold in a compromised browser gives threat actors access to sensitive information and potential avenues into targeted environments.
In this post, we take a deep dive into browser security, exploring the differences between vulnerabilities and exploits, zero
Qualys
Latest Trend in Mac Vulnerabilities and How to Efficiently Address Them
blogs_qualys·2023-09-29·CVSS 8.8
[HIGH] Latest Trend in Mac Vulnerabilities and How to Efficiently Address Them
## Table of Contents
Simplify Patching Your MacOS and 3rd-Party Apps
Smart Automation with Testing for MacOS Devices
A Simple and Improved Way to Patch Your MacOS Devices
Contributors
Usually, every September/October, Apple releases its updated OSes and, with them, a set of new CVEs. This month was no different.
In fact, if we look at 2023, Qualys released on average 32 new QIDs every month for MacOs and its 3rd-party products (see figure below):
In the past few years, there has been a sharp increase in the number of Mac devices used by end users. As such, ensuring those devices are fully patched has become more critical. To keep up with this volume of vulnerabilities, organizations have to opt-in, buy, and operate a dedicated (and in many cases proprietary) Mac tool to help them en
Qualys
Latest Trend in Mac Vulnerabilities and How to Efficiently Address Them | Qualys
blogs_qualys·2023-09-29·CVSS 8.8
[HIGH] Latest Trend in Mac Vulnerabilities and How to Efficiently Address Them | Qualys
#### Table of Contents
- Simplify Patching Your MacOS and 3rd-Party Apps
- Smart Automation with Testing for MacOS Devices
- A Simple and Improved Way to Patch Your MacOS Devices
- Contributors
Usually, every September/October, Apple releases its updated OSes and, with them, a set of new CVEs. This month was no different.
In fact, if we look at 2023, Qualys released on average 32 new QIDs every month for MacOs and its 3rd-party products (see figure below):
Fig 1. Mac Vulns 2023
In the past few years, there has been a sharp increase in the number of Mac devices used by end users. As such, ensuring those devices are fully patched has become more critical. To keep up with this volume of vulnerabilities, organizations have to opt-in, buy, and operate a dedicated (and in many cases proprie
Bleepingcomputer
Apple emergency updates fix 3 new zero-days exploited in attacks
blogs_bleepingcomputer·2023-09-21·CVSS 8.8
[HIGH] Apple emergency updates fix 3 new zero-days exploited in attacks
## Apple emergency updates fix 3 new zero-days exploited in attacks
## Sergiu Gatlan
Apple fixed the three zero-day bugs in macOS 12.7/13.6, iOS 16.7/17.0.1, iPadOS 16.7/17.0.1, and watchOS 9.6.3/10.0.1 by addressing a certificate validation issue and through improved checks.
"Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7," the company revealed in security advisories describing the security flaws.
The list of impacted devices encompasses older and newer device models, and it includes:
iPhone 8 and later
iPad mini 5th generation and later
Macs running macOS Monterey and newer
Apple Watch Series 4 and later
All three zero-days were found and reported by Bill Marczak of the Citizen Lab at The University of Toronto'
Bleepingcomputer
Apple backports BLASTPASS zero-day fix to older iPhones
blogs_bleepingcomputer·2023-09-12·CVSS 8.8
[HIGH] Apple backports BLASTPASS zero-day fix to older iPhones
## Apple backports BLASTPASS zero-day fix to older iPhones
## Bill Toulas
When the phones received and processed the attachment, it installed NSO's Pegasus spyware, even on fully patched iOS (16.6) devices.
Apple released fixes for the two flaws with macOS Ventura 13.5.2, iOS 16.6.1, iPadOS 16.6.1, and watchOS 9.6.2, and CISA published an alert requiring federal agencies to patch by October 2, 2023.
The security updates have now been backported to iOS 15.7.9 and iPadOS 15.7.9 , macOS Monterey 12.6.9 , and macOS Big Sur 11.7.10 to prevent the use of this attack chain on those devices.
It's worth noting that support for iOS 15 ended a year ago, in September 2022, while the vendor still supports Monterey and Big Sur.
The security updates cover all iPhone 6s models, the iPhone 7, the fir
Bleepingcomputer
CISA warns govt agencies to secure iPhones against spyware attacks
blogs_bleepingcomputer·2023-09-11·CVSS 6.5
CVE-2023-41064 [MEDIUM] CISA warns govt agencies to secure iPhones against spyware attacks
## CISA warns govt agencies to secure iPhones against spyware attacks
## Sergiu Gatlan
"Apple is aware of a report that this issue may have been actively exploited," the company said when describing the two Image I/O and Wallet vulnerabilities, tracked as CVE-2023-41064 and CVE-2023-41061 .
The list of impacted devices is quite extensive, as the bugs affect both older and newer models, and it includes:
iPhone 8 and later
iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
Macs running macOS Ventura
Apple Watch Series 4 and later
Apple fixed the two zero-days in macOS Ventura 13.5.2, iOS 16.6.1, iPadOS 16.6.1, and watchOS 9.6.2 with memory handling and improved logic. Both allow attackers to gain arbitrary c
Bleepingcomputer
Apple zero-click iMessage exploit used to infect iPhones with spyware
blogs_bleepingcomputer·2023-09-07·CVSS 8.8
[HIGH] Apple zero-click iMessage exploit used to infect iPhones with spyware
## Apple zero-click iMessage exploit used to infect iPhones with spyware
## Sergiu Gatlan
"The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim."
Citizen Lab also urged Apple customers to update their devices immediately and encouraged those at risk of targeted attacks due to their identity or profession to activate Lockdown Mode .
Apple and Citizen Lab security researchers discovered the two zero-days in the Image I/O and Wallet frameworks.
CVE-2023-41064 is a buffer overflow triggered when processing maliciously crafted images, while CVE-2023-41061 is a validation issue that can be exploited via malicious attachments.
Both allow threat actors to gain arbitrary code execution on unpatched iPhone and iPad devices.
Bleepingcomputer
Apple discloses 2 new zero-days exploited to attack iPhones, Macs
blogs_bleepingcomputer·2023-09-07·CVSS 6.5
CVE-2023-41064 [MEDIUM] Apple discloses 2 new zero-days exploited to attack iPhones, Macs
## Apple discloses 2 new zero-days exploited to attack iPhones, Macs
## Sergiu Gatlan
Citizen Lab also revealed today that the CVE-2023-41064 and CVE-2023-41061 bugs were actively abused as part of as part of a zero-click iMessage exploit chain named BLASTPASS that was used to deploy NSO Group's Pegasus mercenary spyware onto fully-patched iPhones (running iOS (16.6) via PassKit attachments containing malicious images.
CVE-2023-41064 is a buffer overflow weakness that gets triggered when processing maliciously crafted images, and it can lead to arbitrary code execution on unpatched devices.
CVE-2023-41061 is a validation issue that can be exploited using a malicious attachment to also gain arbitrary code execution on targeted devices.
Apple fixed the zero-days in macOS Ventura 13.5.2,
Talos
The federal government’s cybersecurity policies are falling into place just in time to be stalled again
blogs_talos·2023-07-20
The federal government’s cybersecurity policies are falling into place just in time to be stalled again
Welcome to this week’s edition of the Threat Source newsletter.
Last week, the Biden administration released its formal roadmap for its national cybersecurity initiative meant to encourage greater investment in cybersecurity and strengthen the U.S.’s critical infrastructure security (and more).
The roadmap goes a long way toward actualizing a plan the administration released earlier this year and sets tangible goals and programs to put many of these initiatives into action. But because nothing ever moves quickly in government, this roadmap and the associated plan are already hitting a few roadblocks.
First, there’s the ever-present partisan politics. Republican state lawmakers are backing a legal challenge in the court systems to block an Environmental Protection Administration rule tha
Talos
The federal government’s cybersecurity policies are falling into place just in time to be stalled again
blogs_talos·2023-07-20
The federal government’s cybersecurity policies are falling into place just in time to be stalled again
## The federal government’s cybersecurity policies are falling into place just in time to be stalled again
Welcome to this week’s edition of the Threat Source newsletter.
Last week, the Biden administration released its formal roadmap for its national cybersecurity initiative meant to encourage greater investment in cybersecurity and strengthen the U.S.’s critical infrastructure security (and more).
The roadmap goes a long way toward actualizing a plan the administration released earlier this year and sets tangible goals and programs to put many of these initiatives into action. But because nothing ever moves quickly in government, this roadmap and the associated plan are already hitting a few roadblocks.
First, there’s the ever-present partisan politics. Republican state lawmakers are
Checkpoint
17th July – Threat Intelligence Report
blogs_checkpoint·2023-07-17
CVE-2023-36884 17th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th July, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Colorado State University (CSU) has been affected by ransomware gang Cl0p’s MOVEit Managed File Transfer attack. The threat actors compromised the University’s service vendors, which resulted in an unauthorized access to personal information of students and employees dating back to at least 2021. The exposed data includes names,
https://security.gentoo.org/glsa/202401-04https://support.apple.com/en-us/HT213826https://support.apple.com/en-us/HT213841https://support.apple.com/en-us/HT213843https://support.apple.com/en-us/HT213846https://support.apple.com/en-us/HT213848https://security.gentoo.org/glsa/202401-04https://support.apple.com/en-us/HT213826https://support.apple.com/en-us/HT213841https://support.apple.com/en-us/HT213843https://support.apple.com/en-us/HT213846https://support.apple.com/en-us/HT213848https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-37450
2023-07-27
Published
2023-07-13
Added to CISA KEV
Exploited in the wild