Apple iOS Flaws Trigger Federal Alert
HighExecutive Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch several actively exploited vulnerabilities in Apple’s iOS.
These flaws are being leveraged by the “Coruna” exploit kit in campaigns ranging from cyberespionage to cryptocurrency theft.
Vulnerability Details
- Affected Product:Apple iOS and iPadOS versions 13.0 through 17.2.1.
- Identifier:including CVE-2024-23296 and others added to KEV (e.g., CVE-2023-41974, CVE-2023-43000).
- CVSS Score: Up to 8.8 (High).
- Exploitation Status: Actively Exploited.
Risk & Impact
- Triage: Urgent. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring immediate patching by federal agencies.
- Attack Vector: The vulnerabilities are exploited remotely by processing specially crafted web content. The "Coruna" exploit kit delivers the payload through watering hole attacks and fake financial websites.
- Ease of Exploit: The existence of a sophisticated and well-engineered exploit kit ("Coruna") indicates that threat actors can readily deploy these attacks in broad-scale campaigns.
Action Plan
- Immediate Action: Update to the latest iOS/iPadOS version.
- Workaround: Where updating is not possible, enabling Lockdown Mode can prevent the Coruna exploit kit from executing.
- Detection: The Coruna exploit kit payload scans for QR codes in images and searches for cryptocurrency wallet recovery phrases and financial keywords. All identified malicious websites and domains have been added to Google Safe Browsing.
Relevant professional terms
- Exploit Kit
- A software toolkit designed to identify and exploit vulnerabilities on a target system, often delivered through web browsers to automate attacks.
- CISA (Cybersecurity and Infrastructure Security Agency)
- A U.S. federal agency responsible for improving cybersecurity and infrastructure protection across all levels of government, coordinating with the private sector, and protecting against cyber threats.
Source: BleepingComputer
