HomeinetTriangulation spyware: Apple fixes zero-days that allow it

Triangulation spyware: Apple fixes zero-days that allow it

Apple has addressed three new zero-days that were used in attacksthat installed Triangulation spyware on iPhones via iMessage, without the required user response.

See also: Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

Triangulation spyware

"Apple has received a report that this issue may have been exploited against versions of iOS released prior to iOS 15.7," the company says, describing the Kernel and WebKit vulnerabilities known as CVE-2023-32434 and CVE-2023-32435. Kaspersky security researchers Georgy Kucherin, Leonid Bezvershenko , and Boris Larindiscovered and reported the two security flaws.

Kaspersky made a report earlier that included more details about a piece of spyware for iOS, which is being used in a campaign called “Operation Triangulation,” which is under the surveillance of the cybersecurity firm.

“The zero-day, which we have named TriangleDB, is deployed after attackers gain root privileges on the target iOS device by exploiting a kernel vulnerability. It deploys in memory, meaning all traces of it are lost when the device is rebooted,” Kaspersky said.

“Therefore, if the victim reboots their device, the attackers must re-infect it by sending an iMessage with a malicious attachment, thus starting the entire exploit chain again. In case of no reboot, the implant is uninstalled after 30 days, unless this period is extended by the attackers.“.

See also: Google fixes new zero-day vulnerability in Chrome browser

According to Kaspersky, the attacks in question began in 2019 and are still ongoing. In June of that year, it was announced that some iPhones on its network had been infected with previously unknown spyware via iMessage. The attack exploited iOS zero-day bugs.

zero days

Russia's FSB intelligence and security service has alleged that Apple provided a backdoor for the NSA to infect iPhones in Russia with spyware, following the publication of the Kaspersky report. The FSB said it had identified thousands of infected iPhones belonging to Russian government officials and staff from embassies in Israel, China and NATO member countries.

Apple is fixing a vulnerability in WebKit (CVE-2023-32439) reported by an anonymous researcher. The vulnerability could allow attackers to execute malicious code on devices that have not yet been patched, via a type confusion issue.

The company addressed the three zero-days in macOS Ventura 13.4.1, macOS Monterey 12.6.7, macOS Big Sur 11.7.8, iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, watchOS 95. .2 and watchOS 8.8.1 with improved controls, input validation, and state management.

See also: New zero-day MOVEit Transfer is being exploited massively in data theft attacks

The list of affected devices is quite extensive. The issue affects both older and newer device models:

  • iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, iPad mini 5th generation and later
  • iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)
  • Macs running macOS Big Sur, Monterey, and Ventura
  • Apple Watch Series 4 and later, Apple Watch Series 3, Series 4, Series 5, Series 6, Series 7, and SE
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS