Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple reveals two iOS zero-day vulnerabilities that allow attackers to access fully patched devices
https://techxplore.com ^ | MAY 4, 2021 | by Sarah Katz

Posted on 05/05/2021 11:15:11 AM PDT by Red Badger

One week after Apple carried out its largest iOS and iPad update since September 2020's version 14.0 release, the company has followed up with a new patch for two zero-day vulnerabilities that let hackers execute malicious code on fully updated devices. Additionally, the new release of 14.5.1 also mitigates issues with a bug in the recent App Tracking Transparency feature included in the previous version.

Both of these vulnerabilities are located in the browser engine Webkit, which provides web content for App Store, Mail and Safari as well as other various apps running on iOS, Linux and macOS. Apple described this attack as the processing of maliciously crafted web content resulting in arbitrary code execution. As of now, these two zero-days have been patched.

So far, Apple has issued a notice that these vulnerabilities may have already been exploited. The company has also announced that the second zero-day was discovered by Chinese security research firm Qihoo 360, whereas an anonymous source reported the first vulnerability. At this time, Apple has yet to offer details regarding who is carrying out the exploits or who faces a risk of exploitation.

Google's Project Zero vulnerability research team has assessed that these three new vulnerabilities make the total number of seven actively exploited Apple zero-days. In fact, out of 22 zero-days discovered in 2021 alone, nearly 33 percent have targeted Apple mobile OS. This makes iOS the software most targeted by zero-day after Chrome.

Since these vulnerabilities have been patched, Facebook has taken some issue due to the new security restrictions not allowing the Facebook app to track user activity across other installed applications without explicit user permission. Furthermore, another bug may cause graying out of the App Tracking Transparency toggle in the settings menu, even after users have updated to iOS 14.5.1.

Overall, Apple security and vulnerability research teams emphasize that these types of zero-days pose such a threat to both defenders and users due to the lack of knowledge surrounding their presence. After all, if hackers manage to execute evil code or access a privileged system before incident responders and researchers even realize the vulnerabilities in question exist, the attackers can steal a plethora of data, causing potentially immeasurable damage.

Alongside patches for the discovered vulnerabilities, Apple has also confirmed a patch for the App Tracking Transparency feature bug. This fix will enable users to once again opt out of ad tracking on their Apple devices.

Explore further

Apple urges security upgrade to iPhones, iPads

More information:

support.apple.com/en-us/HT212336 support.apple.com/en-us/HT212335 support.apple.com/en-us/HT212339


TOPICS:
KEYWORDS: apple; ios; securityupdate
Navigation: use the links below to view more comments.
first 1-2021-27 next last

1 posted on 05/05/2021 11:15:11 AM PDT by Red Badger
[ Post Reply | Private Reply | View Replies]

To: All

UPDATE: taking out old bugs and putting in new ones................


2 posted on 05/05/2021 11:16:08 AM PDT by Red Badger (Jesus said there is no marriage in Heaven. That's why they call it Heaven.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; ShadowAce; dayglored

Pingy!................


3 posted on 05/05/2021 11:16:34 AM PDT by Red Badger (Jesus said there is no marriage in Heaven. That's why they call it Heaven.....................)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Thank you Sir... :)


4 posted on 05/05/2021 11:29:45 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Fake news. Apple devices are bullet proof and can’t ever be compromised.

/sarc


5 posted on 05/05/2021 11:35:36 AM PDT by unixfox (Abolish Slavery, Repeal the 16th Amendment)
[ Post Reply | Private Reply | To 1 | View Replies]

To: unixfox

Only if you never turn it on......................


6 posted on 05/05/2021 11:37:00 AM PDT by Red Badger (Jesus said there is no marriage in Heaven. That's why they call it Heaven.....................)
[ Post Reply | Private Reply | To 5 | View Replies]

To: unixfox

:)


7 posted on 05/05/2021 11:57:58 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 5 | View Replies]

To: unixfox

Tell that to FR’s biggest Apple pimp Swordmaker.


8 posted on 05/05/2021 11:58:45 AM PDT by Blue Highway
[ Post Reply | Private Reply | To 5 | View Replies]

To: Blue Highway; Admin Moderator; Swordmaker

Don’t be a jerk to a guy who runs a useful ping list. I suppose you use a flip phone?


9 posted on 05/05/2021 12:13:34 PM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Blue Highway

Winner!


10 posted on 05/05/2021 12:31:01 PM PDT by cranked
[ Post Reply | Private Reply | To 8 | View Replies]

To: FreedomPoster

I begrudgingly use an Apple iPhone. Prefer windws and Samsung. Apple sucks. PERIOD!


11 posted on 05/05/2021 12:46:50 PM PDT by Blue Highway
[ Post Reply | Private Reply | To 9 | View Replies]

To: Blue Highway

Gave up winders decades ago.


12 posted on 05/05/2021 1:01:51 PM PDT by AFreeBird
[ Post Reply | Private Reply | To 11 | View Replies]

To: Blue Highway

Android OS sucks worse than Apple. So there. It’s either one of those, or a flip phone. Enjoy the suck.


13 posted on 05/05/2021 1:30:37 PM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 11 | View Replies]

To: FreedomPoster

Android OS isn’t worse than IOS. Give me your reasons why you think so? With IOS you can’t delete app cache and data and then it becomes a bloated pig. The most bloated are browser apps, FB, Youtube etc. When I went from my Samsung S5 to iPhone 11 Pro there was a good 3 months I was cursing the phone because of stupid limitations that weren’t allowed with the Apple. Like retarded things. With battery saver on I can’t disable the 30 second screen timeout limitation. BS like that is infuriating. With Android I’d be able to make changes in developer options, good luck with that in Apple. Having an Apple feels like living in the nanny state dictating to you what you can and cannot do. Android feels like living in America decades ago before the big brother government control we live under now.


14 posted on 05/05/2021 1:51:58 PM PDT by Blue Highway
[ Post Reply | Private Reply | To 13 | View Replies]

To: Blue Highway; Swordmaker

Because Apple has at least some morals when it comes to protection of user data, identity, and privacy, while Google/Android have none whatsoever, that is why.


15 posted on 05/05/2021 1:54:53 PM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 14 | View Replies]

To: FreedomPoster

BS I have more random spam and phising type calls o nce I switched to iphone 11 Pro even with the same number. It was almost within the first month I was getting 10-20 spam type calls per week. With Android I was rarely getting them maybe 2-3 per month. Nice try dude, but that’s a big fail. Any other reason that’s actually based on truth?


16 posted on 05/05/2021 1:59:16 PM PDT by Blue Highway
[ Post Reply | Private Reply | To 15 | View Replies]

To: FreedomPoster

Another reason I preferred my Samsung was I was able to tether my phone’s internet connection to my laptop with no limitations. I haven’t been able to do this with Apple, and have to use Hotspot data that runs out after 15GB. When I was on Sprint with my Samsung I was using 40-70GB a month with no speed restrictions. Now on Apple if I go over 15GB speed is dropped to 128kb/s.


17 posted on 05/05/2021 2:08:29 PM PDT by Blue Highway
[ Post Reply | Private Reply | To 15 | View Replies]

To: Blue Highway

Data speeds and quantities are a function of your deal with the carrier, and are device independent.

Have a nice day.


18 posted on 05/05/2021 2:19:49 PM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 17 | View Replies]

To: FreedomPoster

Nice how you gloss over the actual problems of the IOS I posted and just try to point out a trivial fact about carrier data speeds that is skirting the issue. You can’t tether Iphones. Samsung phones you can. I’m guessing you’re one of the iPhone cultists. Here I am with an iPhone and I can call out any of the BS issues they have. I just saw a new update to 14.5 and I quote, “iOS 14.5 includes the option to unlock iPhone with Apple Watch while wearing a face mask”. Are you freaking kidding me? Apple down with the Fauxci mask police too now it seems. Unf’king believable.


19 posted on 05/05/2021 2:33:23 PM PDT by Blue Highway
[ Post Reply | Private Reply | To 18 | View Replies]

To: FreedomPoster
"Android OS sucks worse than Apple. So there. It’s either one of those, or a flip phone."

Or...   run Linux on open source hardware. Quit being the product.




Pine Phone 64


20 posted on 05/05/2021 2:34:30 PM PDT by Garth Tater (What's mine is mine.)
[ Post Reply | Private Reply | To 13 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-27 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson