Story image

iOS gets another round of critical security updates to block major security holes

27 Jul 17

Apple’s iOS 10.3.3 has undergone an urgent update after massive security holes were discovered in many of the system’s functions.

The security updates affect iPhone 5 and later, iPad 4th generation and later, as well as the iPod Touch 6th generation.

The flaws can allow remote attackers to run arbitrary code or terminate apps through a number of iOS systems, including its contacts, messages, notifications, Safari, telephony, wifi and other system functions including kernels, libxpc, EventKitUI and CoreAudio.

Attackers could also potentially execute code by taking advantage of a device’s wifi chip, while users who stumbled upon malicious web content could find that their browser was frozen due to an infinite number of print dialogues.

In total, there are 24 areas and 47 CVE updates listed for iOS 10.3.3, most of which were discovered by Google’s Project Zero, Baidu Security Lab, university professors and security researchers.

Apple says that it doesn’t discuss or confirm security issues until it has investigated and made relevant patches and updates available.

While some iOS users still believe that devices are still relatively immune from hacking, proof from security organisations shows otherwise.

Earlier this year ESET’s Graham Clueley said in a blog that updates such as these are not about pointing out every single flaw in the system – it’s more of an encouragement for people to update systems at the earliest opportunity.

“Apple products may find themselves in the firing line of attacks less often than their Windows and Android cousins, but that doesn’t mean they’re immune. If can learn anything from the events of the last few days it is surely the need to keep systems up-to-date and make regular backups of your data,” he says.

iOS and other Apple devices have also been targeted by spyware such as Pegasus and XAgent and AceDeceiver – a malware that targeted Apple’s DRM flaws.

Other cases this year included OSX/Dok, which popped up in April 2017. Check Point researchers discovered the Trojan, which was able to get around Apple’s security features and hijack all traffic on a Mac.

A ransomware variant called KeRanger was also able to encrypt Apple devices in March 2016. The ransomware was introduced via an update of Transmission torrent client 2.9.0. It was then able to run alongside the software and secretly encrypt files.

Palo Alto Network's Claud Xiao and Jin Chen explain how KeRanger works:

"The KeRanger application was signed with a valid Mac app development certificate; therefore, it was able to bypass Apple's Gatekeeper protection,” said Palo Alto Networks researchers Claud Xiao and Jin Chen at the time.

Apple quickly revoked the certificate to stop further ransomware attacks.

EU cloud adoption rising, but still far from mainstream
Cloud adoption is surging among some European Union (EU) nations but it still has a way to go to becoming commonplace across the board
Industry cloud market forecast for ‘unusual’ growth
The market for industry cloud solutions is in good stead with that growth showing little signs of slowing.
Dell EMC embeds security in latest servers
Dell EMC's 14th generation of PowerEdge servers has comprehensive management tools to provide security across hardware and firmware.
Businesses focusing on threats from within - survey
Over 50% of respondents reported that 100 days of dwell time or more was representative of their organisation.
The disaster recovery-as-a-service market is on the rise
As time progresses and advanced technologies are implemented, the demand for disaster recovery-as-a-service is also expected to increase.
Dell dominates enterprise storage market, HPE declines
The enterprise storage system market continues to be a goldmine for most vendors with demand relentlessly rising year-on-year.
The key to financial institutions’ path to digital dominance
By 2020, about 1.7 megabytes a second of new information will be created for every human being on the planet.
Is Supermicro innocent? 3rd party test finds no malicious hardware
One of the larger scandals within IT circles took place this year with Bloomberg firing shots at Supermicro - now Supermicro is firing back.