Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Bitcoin Decline Sees Funding Rates Plunge To Three-Month Lows bitcoin news
  • What Does The Bull Div On Ethereum RSI Mean For The Top Altcoin? bitcoin news
  • VMware Releases Patches for New Vulnerabilities Affecting Multiple Products cyber security news
  • How MIDA’s Token Economy is Set to Rejuvenate the Art Market bitcoin news
  • Binance Suspends Direct Deposits and Withdrawals in Brazil – Bitcoin News bitcoin news
  • Bitcoin Broke Above The Multi-Week Resistance; What’s Next bitcoin news
  • Market Sentiment Dangerously Negative As Crypto Fear Index Drops To Two-Year Low bitcoin news
  • New NTLM Relay Attack Lets Attackers Take Control Over Windows Domain cyber security news

Google Researchers Detail 5-Year-Old Apple Safari Vulnerability Exploited in the Wild

Posted on June 20, 2022 By root


Apple Safari Vulnerability

A security flaw in Apple Safari that was exploited in the wild earlier this year was originally fixed in 2013 and reintroduced in December 2016, according to a new report from Google Project Zero.

The issue, tracked as CVE-2022-22620 (CVSS score: 8.8), concerns a case of a use-after-free vulnerability in the WebKit component that could be exploited by a piece of specially crafted web content to gain arbitrary code execution.

In early February 2022, Apple shipped patches for the bug across Safari, iOS, iPadOS, and macOS, while acknowledging that it “may have been actively exploited.”

CyberSecurity

“In this case, the variant was completely patched when the vulnerability was initially reported in 2013,” Maddie Stone of Google Project Zero said. “However, the variant was reintroduced three years later during large refactoring efforts. The vulnerability then continued to exist for 5 years until it was fixed as an in-the-wild zero-day in January 2022.”

While both the 2013 and 2022 bugs in the History API are essentially the same, the paths to trigger the vulnerability are different. Then subsequent code changes undertaken years later revived the zero-day flaw from the dead like a “zombie.”

CyberSecurity

Stating the incident is not unique to Safari, Stone further stressed taking adequate time to audit code and patches to avoid instances of duplicating the fixes and understanding the security impacts of the changes being carried out.

“Both the October 2016 and the December 2016 commits were very large. The commit in October changed 40 files with 900 additions and 1225 deletions. The commit in December changed 95 files with 1336 additions and 1325 deletions,” Stone noted.

“It seems untenable for any developers or reviewers to understand the security implications of each change in those commits in detail, especially since they’re related to lifetime semantics.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: The Metaverse Founders Club Wants To Unlock Cross-Metaverse Interoperability To Provide A Better User Experience
Next Post: Bitflex Commences BETA Testing With Zero-Trading Fees – Press release Bitcoin News

Related Posts

  • How to Protect Your Data When Ransomware Strikes cyber security news
  • What Are Shadow IDs, and How Are They Crucial in 2022? cyber security news
  • New Emotet Variant Stealing Users’ Credit Card Information from Google Chrome cyber security news
  • DOJ Seizes 3 Web Domains Used to Sell Stolen Data and DDoS Services cyber security news
  • New ToddyCat Hacker Group on Experts’ Radar After Targeting MS Exchange Servers cyber security news
  • Microsoft Issues Fix for Actively Exploited ‘Follina’ Vulnerability cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Mad Money’s Jim Cramer Says Crypto Immolation Shows the Fed’s Job to Tame Inflation Is Almost Complete – Markets and Prices Bitcoin News
  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News

Recent Comments

No comments to show.
  • While Bitcoin and Ethereum Dominance Slides, Stablecoin Market Caps Reap the Rewards – Market Updates Bitcoin News bitcoin news
  • FTX US Launches Zero-Commission Equities Trading Platform – Bitcoin News bitcoin news
  • Bitcoin Market Cap Falls By $280 Billion As Crypto Adoption In 2022 Fails bitcoin news
  • IMF Says Central African Republic’s Bitcoin Adoption Poses Risks – Featured Bitcoin News bitcoin news
  • Despite Overcollateralized Reserve, Tron’s USDD Stablecoin Slips to $0.974 per Token – Altcoins Bitcoin News bitcoin news
  • How MIDA’s Token Economy is Set to Rejuvenate the Art Market bitcoin news
  • US Treasury Sanctions First Crypto Mixer – Regulation Bitcoin News bitcoin news
  • GameFi Platform is Gateway to Web 3.0 bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme