Researchers find new bug ‘class’ in Apple devices

freshidea – stock.adobe.com

A group of vulnerabilities in Apple products that stem from the ForcedEntry exploit used by spyware firm NSO constitutes a whole new class of bug, say researchers at Trellix

Alex Scroxton

By

Published: 22 Feb 2023 12:52

Researchers at Trellix have uncovered what they claim to be an entirely new class of privilege escalation vulnerability in Apple devices stemming from the infamous ForcedEntry exploit used by disgraced Israeli spyware manufacturer NSO Group to let its government customers target activists, journalists and political opponents.

The existence of ForcedEntry – CVE-2021-30860 – was disclosed in September 2021 by The Citizen Lab, an interdisciplinary laboratory based at the University of Toronto’s Munk School of Global Affairs and Public Policy in Canada, which was the first to expose NSO’s malfeasance earlier that summer.

But now, Trellix says its Advanced Research Centre vulnerability team has discovered a group of bugs in iOS and macOS that bypass the strengthened code-signing mitigations put in place by Apple to stop the exploitation of ForcedEntry.

Left unaddressed, these vulnerabilities – which range from medium to high severity carrying CVSS scores from 5.1 to 7.1, could allow a threat actor to access sensitive information on a target device, including but not limited to the victim’s messages, location data, call history and photos.

In Trellix’s disclosure notice, senior vulnerability researcher Austin Emmitt said the new bugs involve the NSPredicate tool used by developers to filter code, around which Apple tightened restrictions in the wake of the ForcedEntry fracas by introducing a protocol called NSPredicateVisitor.

“These mitigations used [a] large deny list to prevent the use of certain classes and methods that could clearly jeopardise security,” explained Emmitt.

“However, we discovered that these new mitigations could be bypassed. By using methods that had not been restricted, it was possible to empty these lists, enabling all the same methods that had been available before. This bypass was assigned CVE-2023-23530 by Apple.

“Even more significantly, we discovered that nearly every implementation of NSPredicateVisitor could be bypassed. This bypass was assigned CVE-2023-23531. These two techniques opened a huge range of potential vulnerabilities that we are still exploring.”

So far, the team has found multiple vulnerabilities within the new class of bugs, the first and most significant of which exists in a process designed to catalogue data about behaviour on Apple devices. If an attacker has achieved code execution capability in a process with the right entitlements, they could then use NSPredicate to execute code with the process’s full privilege, gaining access to the victim’s data.

Emmitt and his team also found other issues that could enable attackers with appropriate privileges to install arbitrary applications on a victim’s device, access and read sensitive information, and even wipe a victim’s device. Ultimately, all of the new bugs carry a similar level of impact to ForcedEntry.

Emmitt said the vulnerabilities constituted a “significant breach” of the macOS and iOS security models, which rely on individual applications having fine-grain access to the subset of resources needed, and querying services with more privileges to get anything else.

“Services that accept NSPredicate arguments and check them with insufficient NSPredicateVisitors allow malicious applications and exploit code to defeat process isolation and directly access far more resources than should be allowed. These issues were addressed with macOS 13.2 and iOS 16.3. We would like to thank Apple for working quickly with Trellix to fix these issues,” he wrote.

Fruitful interaction

Synopsys Cybersecurity Research Centre global research head Jonathan Knudsen said the outcome of the disclosures represented a “fruitful interplay” between researchers and Apple, which has been criticised before now for its approach to vulnerability disclosures and patching.

“Software must be built with security in mind at every phase, with the goal of finding and eliminating as many vulnerabilities as possible. Even when you do everything right, however, some vulnerabilities can still be present in the released software,” he said.

“Post-release, security researchers, both benevolent and malicious, might also discover vulnerabilities. Responding quickly to inbound security disclosures is critically important. Some organisations, including Apple, encourage security researchers to submit issues by providing incentives, typically called bug bounties. Recognising and engaging the security research community is an important component of a comprehensive software security initiative,” he said.

Read more on Data breach incident management and recovery

Read More
Larisa Pepper

Latest

NCAA Makes Major Eligibility Announcement to Avoid Another Diego Pavia-Esque Legal Battle

College football has just gotten a new rule that would see the NCAA spend less on legal fees. After spending $16M in legal fees last year,  the NCAA’s new eligibility rule looks to eliminate most of the previous conditions for the extension of eligibility. With this, legal cases, like Diego Pavia’s, will have nothing on

Aaron Rodgers’ Brother Lands New ESPN Role Days After Laura Rutledge Successor Announcement

ESPN is elevating Jordan Rodgers beyond SEC Nation into national college football broadcasts, making another shakeup to deliver the best broadcasting product on those Saturdays and Sundays. Just a few weeks ago, ESPN elevated Laura Rutledge’s focus to covering Monday Night Football with Troy Aikman. That meant Laura had to leave SEC Network after a

FOX Nation Pulls Off First-of-Its-Kind Live Preshow for PBR Space Cowboys

FOX News personality Abby Hornacek grew up dreaming of being just like her favorite sports sideline reporter. Her inspiration wasn’t someone talking football. Or any other stick and ball sport, even as the daughter of a former NBA all-star.  Hornacek’s fascination was professional bull riding. She aspired to follow in the footsteps of Leah Garcia

2027 NFL Draft Prospect Interview: Cam Williams, DB, Henderson State University

2027 NFL Draft Prospect Interview: Cam Williams, DB, Henderson State University Name: Cam Williams Position: DB College: Henderson State University (Transfer from Benedict College) Height: 5′ 10″ Weight: 185 lbs X: @Camislandd Instagram: @camislandd What made you decide you wanted to be a football player? I was eight years old, at first it was a

Newsletter

Don't miss

NCAA Makes Major Eligibility Announcement to Avoid Another Diego Pavia-Esque Legal Battle

College football has just gotten a new rule that would see the NCAA spend less on legal fees. After spending $16M in legal fees last year,  the NCAA’s new eligibility rule looks to eliminate most of the previous conditions for the extension of eligibility. With this, legal cases, like Diego Pavia’s, will have nothing on

Aaron Rodgers’ Brother Lands New ESPN Role Days After Laura Rutledge Successor Announcement

ESPN is elevating Jordan Rodgers beyond SEC Nation into national college football broadcasts, making another shakeup to deliver the best broadcasting product on those Saturdays and Sundays. Just a few weeks ago, ESPN elevated Laura Rutledge’s focus to covering Monday Night Football with Troy Aikman. That meant Laura had to leave SEC Network after a

FOX Nation Pulls Off First-of-Its-Kind Live Preshow for PBR Space Cowboys

FOX News personality Abby Hornacek grew up dreaming of being just like her favorite sports sideline reporter. Her inspiration wasn’t someone talking football. Or any other stick and ball sport, even as the daughter of a former NBA all-star.  Hornacek’s fascination was professional bull riding. She aspired to follow in the footsteps of Leah Garcia

2027 NFL Draft Prospect Interview: Cam Williams, DB, Henderson State University

2027 NFL Draft Prospect Interview: Cam Williams, DB, Henderson State University Name: Cam Williams Position: DB College: Henderson State University (Transfer from Benedict College) Height: 5′ 10″ Weight: 185 lbs X: @Camislandd Instagram: @camislandd What made you decide you wanted to be a football player? I was eight years old, at first it was a

Announcing the 2026 Digiday Top Workplaces

By Digiday Awards  •  June 23, 2026  • Digiday Top Workplaces is an annual list recognizing the best companies to work for across media, marketing and technology. The companies recognized this year are setting the standard for what strong workplaces look like: those that lead with purpose, put their people first and shape the future

Business Insurance-AZ Achieves Record Response Times for 2026 Arizona Construction Bids

Business Insurance-AZ achieves milestone response speeds for commercial construction bids across Arizona, accelerating documentation delivery to keep local projects moving forward without delay. Phoenix, AZ, June 06-2026, ZEX PR WIRE — Business Insurance-AZ has achieved record-breaking processing speeds and response times for commercial construction bids throughout Arizona, directly supporting the state’s massive infrastructure and advanced manufacturing boom

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot