Researchers find new bug ‘class’ in Apple devices

freshidea – stock.adobe.com

A group of vulnerabilities in Apple products that stem from the ForcedEntry exploit used by spyware firm NSO constitutes a whole new class of bug, say researchers at Trellix

Alex Scroxton

By

Published: 22 Feb 2023 12:52

Researchers at Trellix have uncovered what they claim to be an entirely new class of privilege escalation vulnerability in Apple devices stemming from the infamous ForcedEntry exploit used by disgraced Israeli spyware manufacturer NSO Group to let its government customers target activists, journalists and political opponents.

The existence of ForcedEntry – CVE-2021-30860 – was disclosed in September 2021 by The Citizen Lab, an interdisciplinary laboratory based at the University of Toronto’s Munk School of Global Affairs and Public Policy in Canada, which was the first to expose NSO’s malfeasance earlier that summer.

But now, Trellix says its Advanced Research Centre vulnerability team has discovered a group of bugs in iOS and macOS that bypass the strengthened code-signing mitigations put in place by Apple to stop the exploitation of ForcedEntry.

Left unaddressed, these vulnerabilities – which range from medium to high severity carrying CVSS scores from 5.1 to 7.1, could allow a threat actor to access sensitive information on a target device, including but not limited to the victim’s messages, location data, call history and photos.

In Trellix’s disclosure notice, senior vulnerability researcher Austin Emmitt said the new bugs involve the NSPredicate tool used by developers to filter code, around which Apple tightened restrictions in the wake of the ForcedEntry fracas by introducing a protocol called NSPredicateVisitor.

“These mitigations used [a] large deny list to prevent the use of certain classes and methods that could clearly jeopardise security,” explained Emmitt.

“However, we discovered that these new mitigations could be bypassed. By using methods that had not been restricted, it was possible to empty these lists, enabling all the same methods that had been available before. This bypass was assigned CVE-2023-23530 by Apple.

“Even more significantly, we discovered that nearly every implementation of NSPredicateVisitor could be bypassed. This bypass was assigned CVE-2023-23531. These two techniques opened a huge range of potential vulnerabilities that we are still exploring.”

So far, the team has found multiple vulnerabilities within the new class of bugs, the first and most significant of which exists in a process designed to catalogue data about behaviour on Apple devices. If an attacker has achieved code execution capability in a process with the right entitlements, they could then use NSPredicate to execute code with the process’s full privilege, gaining access to the victim’s data.

Emmitt and his team also found other issues that could enable attackers with appropriate privileges to install arbitrary applications on a victim’s device, access and read sensitive information, and even wipe a victim’s device. Ultimately, all of the new bugs carry a similar level of impact to ForcedEntry.

Emmitt said the vulnerabilities constituted a “significant breach” of the macOS and iOS security models, which rely on individual applications having fine-grain access to the subset of resources needed, and querying services with more privileges to get anything else.

“Services that accept NSPredicate arguments and check them with insufficient NSPredicateVisitors allow malicious applications and exploit code to defeat process isolation and directly access far more resources than should be allowed. These issues were addressed with macOS 13.2 and iOS 16.3. We would like to thank Apple for working quickly with Trellix to fix these issues,” he wrote.

Fruitful interaction

Synopsys Cybersecurity Research Centre global research head Jonathan Knudsen said the outcome of the disclosures represented a “fruitful interplay” between researchers and Apple, which has been criticised before now for its approach to vulnerability disclosures and patching.

“Software must be built with security in mind at every phase, with the goal of finding and eliminating as many vulnerabilities as possible. Even when you do everything right, however, some vulnerabilities can still be present in the released software,” he said.

“Post-release, security researchers, both benevolent and malicious, might also discover vulnerabilities. Responding quickly to inbound security disclosures is critically important. Some organisations, including Apple, encourage security researchers to submit issues by providing incentives, typically called bug bounties. Recognising and engaging the security research community is an important component of a comprehensive software security initiative,” he said.

Read more on Data breach incident management and recovery

Read More
Larisa Pepper

Latest

Nivea’s Health: What Type of Cancer Is the R&B Singer Battling?

The fan-favorite 'Don't Mess with My Man' artist opened up about her cancer battle...

Cyclosporiasis Outbreak: Foods to Be Aware of Amid Lettuce Recall 2026

A parasite tied to fresh produce is spreading in more than 40 states, and lettuce is now under the microscope. Here's what health officials are saying...

How to Prevent Cyclosporiasis: The Symptoms to Look for & Treatment

A microscopic parasite is making people sick across the country this summer, and health experts say a few simple habits can lower your risk of catching it...

Kushner project being developed on disputed land, Albanian villagers say

ZVERNEC, Albania: When Kostaq Konomi approached what he says is his land on the seafront in southern Albania last month, he was met with a barbed ‌wire fence and men in black uniforms who refused him entry.The land, he later learned from news reports, was now part of a luxury resort planned by international investors

Newsletter

Don't miss

Nivea’s Health: What Type of Cancer Is the R&B Singer Battling?

The fan-favorite 'Don't Mess with My Man' artist opened up about her cancer battle...

Cyclosporiasis Outbreak: Foods to Be Aware of Amid Lettuce Recall 2026

A parasite tied to fresh produce is spreading in more than 40 states, and lettuce is now under the microscope. Here's what health officials are saying...

How to Prevent Cyclosporiasis: The Symptoms to Look for & Treatment

A microscopic parasite is making people sick across the country this summer, and health experts say a few simple habits can lower your risk of catching it...

Kushner project being developed on disputed land, Albanian villagers say

ZVERNEC, Albania: When Kostaq Konomi approached what he says is his land on the seafront in southern Albania last month, he was met with a barbed ‌wire fence and men in black uniforms who refused him entry.The land, he later learned from news reports, was now part of a luxury resort planned by international investors

Oluremi Odunsi Oluwalogbon Calls for Inclusive Electoral System, Urges Stronger Youth Participation Ahead of 2027 Elections

Conversations around youth participation, electoral inclusion, and democratic responsibility took a more reflective tone at the Renewed Hope Campus Dialogue held in Abuja, where stakeholders gathered to examine the future of civic engagement ahead of the 2027 general elections. At the Federal Ministry of Environment, Maitama...

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...

Utah Marketers to Host Free Business Networking Event in Layton on June 24

The custom web design company is hosting free monthly networking events for Northern Utah business leaders, with the next event scheduled for June 24 from 4 to 6 p.m. Utah Marketers is hosting a free local business networking event on June 24 from 4 to 6 p.m. at the company’s Layton office. The event is