Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS

Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS
Apple logo. Credit: Unsplash.com

While a fix emerged three weeks ago for the WebKit security bug affecting Apple products such as iPhone and Mac, Apple has yet to implement the fix. Researchers at the security firm Theori have found that WebKit mainly causes Safari to crash. However, following a re-check after the supplied fix, they discovered that the bug still remains on both iOS and MacOS.

“Patch-gapping” is the term for the time period between when a fix becomes available and the application of that fix to affected systems and products. In this case, Theori cautions Apple about waiting too long to make use of the fix for WebKit, lest attackers have more time and opportunity to compromise impacted systems.

This vulnerability arose from WebKit which is a confusion bug taking advantage of AudioWorklet, the interface allowing developers to alter, control, render and play audio with the lowest possible latency. Unfortunately, attackers can exploit the WebKit bug to remotely execute evil code on affected devices.

That said, attackers using WebKit would still have to circumvent Pointer Authentication Codes (PAC), an exploit mitigation system wherein users must input the correct cryptographic signature before code can be rendered in memory. That means that in the absence of either this signature or some kind of a bypass, attackers will fortunately not be able to run their malicious code.

Researchers have confirmed that this exploit builds arbitrary read/write primitives which attackers could use to build a chain of further exploits. Moreover, they stated that PAC bypass methods count as a distinct issue that should be disclosed separately.

Thus far, WebKit has appeared in six of the eight Apple exploits already uncovered in 2021 alone.


Apple reveals two iOS zero-day vulnerabilities that allow attackers to access fully patched devices


More information:
blog.theori.io/research/webkit-type-confusion/

© 2021 Science X Network

Citation:
Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS (2021, May 28)
retrieved 28 May 2021
from https://techxplore.com/news/2021-05-apple-webkit-bug-affecting-iphone.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

Stay connected with us on social media platform for instant update click here to join our  Twitter, & Facebook

We are now on Telegram. Click here to join our channel (@TechiUpdate) and stay updated with the latest Technology headlines.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechiLive.in is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.