What you need to know
- Two Google bounty hunters disovered six bugs within iOS that could be exploited by malicious third parties.
- Four of the bugs could be exploited through iMessage and the other two relied on the memory of the device.
- Five of the six bugs were fixed with the most recent iOS 12.4 update..
Two security researchers part of Google's Project Zero group discovered six vulnerabilities within iOS that could be easily exploited by malicious parties. Though five of the six were patched with the iOS 12.4 update, one wasn't completely patched, per ZDNet.
Details about one of the "interactionless" vulnerabilities have been kept private because Apple's iOS 12.4 patch did not completely resolve the bug, according to Natalie Silvanovich, one of the two Google Project Zero researchers who found and reported the bugs.
The four bugs are CVE-2019-8641 (details kept private), CVE-2019-8647 , CVE-2019-8660, and CVE-2019-8662 . The linked bug reports contain technical details about each bug, but also proof-of-concept code that can be used to craft exploits.
"Interactionless" means malicious parties do not need any action from the user to exploit the bug. With four of the bugs, someone would just have to send a malicious code via iMessage to another iPhone and once the message is open, the vulnerability is ready to be exploited.
The other two bugs rely the memory of the device.
The fifth and sixth bugs, CVE-2019-8624 and CVE-2019-8646 , can allow an attacker to leak data from a device's memory and read files off a remote device —also with no user interaction.
Thankfully they were brought to Apple's attention but before it became a real issue and were patched in a timely manner. It continues to show that even when a company as big as Apple puts resources in creating a safe and secure software, it is still not immune to rogue bugs.
The two security researchers in question, Natalie Silvanovich and Samuel Groß were handsomely rewarded for their contribution. They will talk more about the bugs in detail at the upcoming Black Hat conference in Las Vegas next week.
If you haven't updated to iOS 12.4, now would be a good time to do so.
We may earn a commission for purchases using our links. Learn more.
TikTok is being banned in the U.S. from Sunday, September 20
The U.S. Department of Commerce will ban TikTok and WeChat from U.S app stores from Sunday.
Apple's RomaEst store in Italy to close permanently, October 17
Apple's RomaEst store will close October 17, paving the way for Apple's stunning new Apple store on the Via Del Corso.
Fortnite: Save the World no longer playable on Mac from September 23
Epic Games has said support for its tower defence game, Fortnite: Save the World, will end on Mac next week following Epic Games fallout and lawsuit against Apple.
New iPad (2020)? Pick up a case and protect it from the start!
Looking for the best iPad 2020 case? We've rounded up some of the best cases for Apple's 8th generation iPad here.