What you need to know
- Two Google bounty hunters disovered six bugs within iOS that could be exploited by malicious third parties.
- Four of the bugs could be exploited through iMessage and the other two relied on the memory of the device.
- Five of the six bugs were fixed with the most recent iOS 12.4 update..
Two security researchers part of Google's Project Zero group discovered six vulnerabilities within iOS that could be easily exploited by malicious parties. Though five of the six were patched with the iOS 12.4 update, one wasn't completely patched, per ZDNet.
"Interactionless" means malicious parties do not need any action from the user to exploit the bug. With four of the bugs, someone would just have to send a malicious code via iMessage to another iPhone and once the message is open, the vulnerability is ready to be exploited.
The other two bugs rely the memory of the device.
Thankfully they were brought to Apple's attention but before it became a real issue and were patched in a timely manner. It continues to show that even when a company as big as Apple puts resources in creating a safe and secure software, it is still not immune to rogue bugs.
The two security researchers in question, Natalie Silvanovich and Samuel Groß were handsomely rewarded for their contribution. They will talk more about the bugs in detail at the upcoming Black Hat conference in Las Vegas next week.
If you haven't updated to iOS 12.4, now would be a good time to do so.
Master your iPhone in minutes
iMore offers spot-on advice and guidance from our team of experts, with decades of Apple device experience to lean on. Learn more with iMore!