Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable Blog

Subscribe

Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed

A researcher has disclosed a buffer overflow vulnerability in Apple’s XNU operating system kernel that allows attackers on a local network to reboot Apple’s iOS and macOS devices and could potentially lead to remote code execution.

Background

On October 30, researcher Kevin Backhouse of Semmle published a blog on his discovery of a buffer overflow vulnerability in Apple’s XNU operating system kernel (CVE-2018-4407). Specifically, the vulnerability exists in the networking code for XNU for how packets are handled. The vulnerability affects OS X, macOS and iOS devices. Backhouse released a proof of concept (PoC) video demonstrating how this vulnerability can be used to crash macOS and iOS devices on a local network.

The PoC has been withheld to allow time for Apple users to upgrade their devices.

Impact assessment

According to Backhouse, this vulnerability affects iOS devices running iOS 11 and earlier. It also affects legacy devices running Apple’s OS X operating system from El Capitan and earlier, as well as macOS Sierra and High Sierra. The vulnerability was reported to Apple in August 2018 and it had been patched in iOS 12 and macOS Mojave.

Vulnerability details

This vulnerability allows a local network attacker to send a specially crafted Internet Protocol (IP) packet to unsuspecting Apple users that triggers a device reboot (or denial of service). While not demonstrated, Backhouse reports that this vulnerability could lead to remote code execution because an attacker can “control the size and content of the heap buffer overflow.” Additionally, he asserts, “the vulnerability is in such a fundamental part of the networking code that anti-virus software will not protect you[...] It also doesn't matter what software you are running on the device - the malicious packet will still trigger the vulnerability even if you don't have any ports open.”

Urgently required actions

Apple users should upgrade to the latest versions of their respective operating systems. In this case, both iOS 12 and macOS Mojave (10.14) have addressed this vulnerability. Apple has also addressed this vulnerability in macOS Sierra and macOS High Sierra.

Identifying affected systems

A list of Tenable plugins to identify this vulnerability will appear here as they’re released.

Get more information

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

Related Articles

Cybersecurity News You Can Use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Tenable Vulnerability Management trials created everywhere except UAE will also include Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose your subscription option:

Buy Now

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy.

Tenable Vulnerability Management trials created everywhere except UAE will also include Tenable Lumin and Tenable Web App Scanning.

Tenable Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

100 assets

Choose your subscription option:

Buy Now