4.9 • 696 Ratings
🗓️ 22 September 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Friday, September 22nd, 2023 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
0:13.6 | This almost appears like a weekly event now, but we got more patches from Apple fixing three different vulnerabilities that are already |
0:24.7 | exploited in the wild. The three vulnerabilities actually sort of nicely chain one after |
0:31.5 | another. We do have sort of for initial access vulnerability in a web kit that allows arbitrary code execution. |
0:40.3 | So a user basically would visit a website and then the attacker gains access inside the Safari sandbox. |
0:50.3 | Then to use the second vulnerability, which is elevation of privilege vulnerability, so that's a kernel vulnerability. |
0:58.5 | So that then likely allows breaking out of the sandbox and get full system access. |
1:05.4 | And then lastly, we do have a vulnerability that allows bypassing of the signature validation for applications. |
1:13.7 | That's how either, sort of for initial access, a malicious application could be installed, |
1:18.3 | or then, you know, as a result, after the attacker has access to the system, they could use |
1:25.1 | a malicious application and sort of gain a foothold on the affected phone. |
1:30.5 | Now, the patches are being released for pretty much all operating systems, macOS, watchOS, and iOS |
1:37.0 | iPadOS. |
1:38.3 | But Apple states in its advisory that this particular vulnerability is currently only being exploited against iOS |
1:47.7 | before 16.7. That being said, it does also potentially affect iOS 17, which was just |
1:58.8 | released. And then as typical for WebKit vulnerabilities, we also get an update for Safari. |
2:04.7 | That's mostly than targeting older versions of Mac OS. |
2:08.4 | And that particular update for Safari, of course, only addresses the WebKit problem. |
2:15.0 | So get patching. |
2:15.9 | Not sure why this wasn't released sort of as a rapid security |
2:18.8 | update, but as a more complete operating system update. So a little bit more downloading |
2:25.2 | you need to do here. And talking about Apple Sarah Days, we do have more details regarding |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.