New Privilege Escalation Bug Class Found on macOS and iOS

of cybersecurity researchers Trellix We shared our findings on six vulnerabilities and a new bug class for macOS and iOS.

In an advisory released today, the company said a new class of privilege escalation bugs is based on the ForcedEntry attack, which exploits features in macOS and iOS to deploy the NSO group’s mobile devices. Pegasus malware.

According to the technical article, the mitigations introduced by Apple after the discovery of ForcedEntry were insufficient to prevent several related attacks.

Notably, the new bug class contains a number of zero-day vulnerabilities similar to those exploited in the aforementioned attacks, with CVSS scores between 5.1 and 7.1.

“The vulnerabilities described above represent a major violation of the macOS and iOS security model, which requires individual applications to gain fine-grained access to a subset of the resources they need and to obtain anything else. We rely on querying highly privileged services,” explains Austin Emmitt, senior at Trellix. Vulnerability researcher.

of Defects found Access to SMS, iMessage, location data, photos, and videos was affected. An attacker could use these bugs to delete certain messages, call history, voicemails, or wipe the device’s internal storage. These bugs were disclosed to Apple and fixed in macOS 13.2 and iOS 16.3 respectively.

“Trellix’s disclosure of a privilege escalation vulnerability affecting macOS and iOS demonstrates a useful interaction between security researchers and Apple. synopsis Cyber ​​Security Research Center.

“Software must be built with security in mind at every stage, and the goal is to find and eliminate as many vulnerabilities as possible. There may still be vulnerabilities in the software,” Knudsen said. Information security on mail.

Security experts also highlighted how security researchers find additional vulnerabilities after release.

“It is very important to respond quickly to inbound security disclosures. Some organizations, including Apple, encourage security researchers to submit issues by offering incentives, commonly referred to as bug bounties. We do,” added Knudsen. “Recognizing and engaging the security research community is a key component of her initiative on comprehensive software security.”

The Trellix advisory comes weeks after Sophos researchers claimed to have found it. First ‘cryptorom’ scam application On Apple’s App Store.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *