As explained by Backhouse along with the POC for this bug residing in the ICMP packet-handling module,
“To trigger the vulnerability, an attacker merely needs to send a malicious IP packet to the IP address of the target device. No user interaction is required. The attacker only needs to be connected to the same network as the target device.”He has shared the below video demonstrating the exploit.
After triggering the bug, an attacker could crash the device or force reboot. Besides, according to the researcher, an attacker could even remotely elicit this vulnerability. Hence, it may lead to the remote execution of arbitrary codes as well.
“The vulnerabilities allow an attacker to mount a maliciously-crafted NFS volume to gain kernel-level privileges. This privilege level is higher than a normal administrator user account. Among other things, it allows an attacker to read, write, and delete arbitrary files on disk and in memory, install new applications, or wipe and reset the device to factory settings. No special permissions are required in macOS to mount an NFS share, so the vulnerabilities can be exploited by any user, including the built-in guest account, which does not require a password.”The researcher has also given a POC for these vulnerabilities alongside demonstrating the exploit in this video.
Whereas, for the other NFS vulnerabilities, the affected operating system includes macOS versions 10.13.5 and earlier. Apple patched the flaws with the macOS version 10.13.6 update in July. However, Apple preferred not to disclose the vulnerabilities until November.
Make sure you upgrade to the latest versions to protect your Apple devices from these XNU kernel vulnerabilities.
Let us know your thoughts in the comments section.