What you need to know
- Two Google bounty hunters disovered six bugs within iOS that could be exploited by malicious third parties.
- Four of the bugs could be exploited through iMessage and the other two relied on the memory of the device.
- Five of the six bugs were fixed with the most recent iOS 12.4 update..
Two security researchers part of Google's Project Zero group discovered six vulnerabilities within iOS that could be easily exploited by malicious parties. Though five of the six were patched with the iOS 12.4 update, one wasn't completely patched, per ZDNet.
Details about one of the "interactionless" vulnerabilities have been kept private because Apple's iOS 12.4 patch did not completely resolve the bug, according to Natalie Silvanovich, one of the two Google Project Zero researchers who found and reported the bugs.
The four bugs are CVE-2019-8641 (details kept private), CVE-2019-8647 , CVE-2019-8660, and CVE-2019-8662 . The linked bug reports contain technical details about each bug, but also proof-of-concept code that can be used to craft exploits.
"Interactionless" means malicious parties do not need any action from the user to exploit the bug. With four of the bugs, someone would just have to send a malicious code via iMessage to another iPhone and once the message is open, the vulnerability is ready to be exploited.
The other two bugs rely the memory of the device.
The fifth and sixth bugs, CVE-2019-8624 and CVE-2019-8646 , can allow an attacker to leak data from a device's memory and read files off a remote device —also with no user interaction.
Thankfully they were brought to Apple's attention but before it became a real issue and were patched in a timely manner. It continues to show that even when a company as big as Apple puts resources in creating a safe and secure software, it is still not immune to rogue bugs.
The two security researchers in question, Natalie Silvanovich and Samuel Groß were handsomely rewarded for their contribution. They will talk more about the bugs in detail at the upcoming Black Hat conference in Las Vegas next week.
If you haven't updated to iOS 12.4, now would be a good time to do so.
You might soon be able to set default apps on iPhones, iPads, and HomePods
Hell has frozen over. Pigs are flying. And cats and dogs are living together in perfect harmony
Apple reopens 2 more stores in China, bringing total to 17.
Apple has reopened a further two stores in China, bringing the total of stores now operating in the country up to 17.
A new Twitter for Mac update fixes an annoying notifications bug
Twitter today released an updated version of its Mac app, complete with a fix for an irritating notifications issue.
Your Fitbit Alta HR just got a little more bling with these bracelet bands
Some people think that once you buy a fitness tracker that you have to stick to traditional bands, and you know what we call those people? Wrong! There's such a variety of stylish bracelet bands and options out there for your Fitbit Alta HR.