Home  ›  News  ›

Apple Issues Urgent iOS Patch for Major Security Vulnerability

Article Comments  

Sep 8, 2023, 7:37 AM   by Rich Brome
updated Sep 8, 2023, 7:43 AM

Apple has released iOS 16.6.1 for iPhones, which fixes an "actively exploited zero-click vulnerability". All iPhone and iPad owners should update their OS software immediately, as this is one of the most severe types of security issues. The vulnerability can be exploited with zero interaction from the victim; the attacker merely needs to send an iMessage with a maliciously crafted image. The Citizen Lab discovered the vulnerability — which they have dubbed "Blastpass" — being actively exploited in the wild and used to install NSO Group's Pegasus "mercenary spyware", which gives the attacker nearly complete access to the target device. Citizen Lab notes that iPhones in Lockdown Mode would not have been vulnerable to this exploit. Lockdown Mode is an existing feature of iOS that cuts off likely attack vectors. It's designed for people likely to be targeted for who they are or what they do. This particular exploit involves "a validation issue" with the PassKit API in Wallet, in combination with a buffer overflow issue in Apple's image-processing framework. Buffer overflows are a common cause of security vulnerabilities across most OSes.

Related

more news about:

Apple
iOS
 

Comments

This forum is closed.

This forum is closed.

No messages

 
 
Page  1  of 1

Subscribe to news & reviews with RSS Follow @phonescoop on Threads Follow @phonescoop on Mastodon Phone Scoop on Facebook Follow on Instagram

 

Playwire

All content Copyright 2001-2024 Phone Factor, LLC. All Rights Reserved.
Content on this site may not be copied or republished without formal permission.