Virtual Event: Threat Detection and Incident Response Summit - Watch Sessions
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Apple Warns of macOS Kernel Zero-Day Exploitation

Apple’s security response engine revved into high gear Monday with patches for security defects in a wide range of products, including fixes for a pair of critical macOS kernel vulnerabilities already being exploited in the wild.

Apple’s security response engine revved into high gear Monday with patches for security defects in a wide range of products, including fixes for a pair of critical macOS kernel vulnerabilities already being exploited in the wild.

Apple acknowledged the macOS zero-days in an advisory but did not share technical details or indicators of compromise to help defenders hunt for signs of infections.

The two vulnerabilities — CVE-2022-32894 and CVE-2022-32917 — affect macOS Big Sur and were reported to Cupertino by an anonymous researcher. “An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited,” the company warned.

Apple said the bugs were addressed with improved bounds checks.

[ READ: Can ‘Lockdown Mode’ Solve Apple’s Mercenary Spyware Problem ]

The macOS Big Sur 11.7 update also covers eight additional security flaws, some serious enough to expose Apple customers to code execution attacks and privacy bypasses.

Apple also released iOS 16 with fixes for a dozen documented security vulnerabilities.  Interestingly, the CVE-2022-32917 kernel flaw is listed among the iOS fixes but Apple did not flag this as being exploited in the wild.

Advertisement. Scroll to continue reading.

The iOS 16 update covers security holes in Contacts, Kernel, Maps, MediaLibrary, Safari, Safari Extensions, Shortcuts and WebKit.

The Cupertino software vendor also released Safari 16 with patches for four separate vulnerabilities that expose users to code execution, user tracking or UI spoofing attacks.

The company also released security-themed updates to tvOS, watcOS, macOS Monterey, and older versions of iOS and Safari.

Related: Can ‘Lockdown Mode’ Solve Apple’s Mercenary Spyware Problem

Related: Apple Patches ‘Actively Exploited’ Mac, iOS Security Flaw

Related: Apple Patches 42 Security Flaws in Latest iOS Refresh

Written By

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a security community engagement expert who has built programs at major global brands, including Intel Corp., Bishop Fox and GReAT. Ryan is a founding-director of the Security Tinkerers non-profit, an advisor to early-stage entrepreneurs, and a regular speaker at security conferences around the world.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.

Register

Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Cyberwarfare

WASHINGTON - Cyberattacks are the most serious threat facing the United States, even more so than terrorism, according to American defense experts. Almost half...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...