CISA Mandates Patches for Exploited iOS Flaws
Executive Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch three actively exploited vulnerabilities in Apple’s iOS (added to KEV catalog).
The flaws, identified as CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 (part of Coruna exploit kit chains; additional older kit vulns include CVE-2024-23225/23296), are being leveraged in spyware and crypto-theft campaigns using the “Coruna” exploit kit.
Vulnerability Details
- Affected Product:Apple iOS, iPadOS, macOS, watchOS, tvOS, and visionOS. Specific versions prior to iOS/iPadOS 17.4 and 16.7.6 are affected.
- Identifier: CVE-2021-30952, CVE-2023-41974, CVE-2023-43000
- CVSS Score:Available on NVD (high/critical range).
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Critical: Immediate patching is required as per CISA directive.
- Attack Vector: The vulnerabilities are memory corruption issues in the Kernel and RTKit. An attacker with arbitrary kernel read and write capabilities can exploit these flaws to bypass kernel memory protections.
- Ease of Exploit: The vulnerabilities are part of a sophisticated "Coruna" exploit kit, suggesting ease of use for threat actors with access to this tool.
Action Plan
- Immediate Action: Upgrade to iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4 or newer versions. For older devices, update to iOS 16.7.6 and iPadOS 16.7.6.
- Workaround: No workarounds are available; patching is the only mitigation.
- Detection: Monitor for signs of compromise associated with known spyware and anomalous device behavior.
Relevant professional terms
- Exploit Kit
- A software toolkit designed to identify and leverage vulnerabilities on a target system, often automating the process of deploying malware.
- Cyberespionage
- The use of computer networks to gain illicit access to confidential information, typically held by a government or other organization.
Source: BleepingComputer
