Apple has released security updates to fix a zero-day vulnerability in the Safari web browser exploited during this year's Pwn2Own Vancouver hacking competition.
The company addressed the security flaw on systems running macOS Monterey and macOS Ventura with improved checks.
While Apple only said that the vulnerability was reported by Manfred Paul, working with Trend Micro's Zero Day Initiative, this is one of the bugs the security researcher chained with an integer underflow bug to gain remote code execution and earn $60,000 during Pwn2Own.
Pointer authentication codes are used on the arm64e architecture to detect and guard against unexpected changes to pointers in memory, with the CPU triggering app crashes following memory corruption events linked to authentication failures.
While Safari 17.5 is also available for iOS 17.5, iPadOS 17.5, macOS Sonoma 14.5, and visionOS 1.2, Apple has yet to confirm if it also patched the CVE-2024-27834 bug on these platforms.
Security researchers collected $1,132,500 after exploiting and reporting 29 zero-days at this year's Vancouver hacking contest.
Manfred Paul emerged as the winner and earned $202,500 in cash after demoing an RCE zero-day combo against Apple's Safari web browser and a double-tap RCE exploit targeting an Improper Validation of Specified Quantity in Input weakness in the Google Chrome and Microsoft Edge web browsers during the first day of the hacking competition.
On the second day, Manfred Paul exploited an out-of-bounds write zero-day bug to gain RCE and escaped Mozilla Firefox's sandbox via an exposed dangerous function weakness.
Google and Mozilla fixed the zero-days exploited at Pwn2Own Vancouver 2024 within days after the contest ended, with Google releasing patches five days later and Mozilla after just one day.
Vendors rarely hurry to fix security flaws exploited at Pwn2Own since Trend Micro's Zero Day Initiative publicly discloses bug details after 90 days.
On Monday, Apple also backported security patches released in March to older iPhones and iPads, fixing an iOS zero-day tagged as exploited in attacks.
Apple backports fix for zero-day exploited in attacks to older iPhones.
PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers.
Microsoft fixes Windows zero-day exploited in QakBot malware attacks.
VMware fixes three zero-day bugs exploited at Pwn2Own 2024.
Apple and Google add alerts for unknown Bluetooth trackers to iOS, Android.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Tue, 14 May 2024 16:00:40 +0000