Pages

Friday, August 26, 2016

Apple Mobile Devices - Patch 'em Up NOW

0 comments
Apple has issued an "important security update", iOS 9.3.5, to neutralize a new piece of malware that can remotely jailbreak iPhones allowing an attacker full access to your device to read texts and email, record calls, track your location and activate your phone's camera and microphone.

The update patches the three previously unknown zero-day vulnerabilities that together are referred to as "Trident".

To check if you're at risk look at Settings > General > About > Version   If you're on version 9.3.5 then you're OK.  If you're on a different version you should update now.  You can pull the update through Settings > General > Software Update then just follow the instructions to download and install it.

For those interested we'll go into the details a little:
The three exploited vulnerabilities are:
  • CVE-2016-4655, Memory Corruption in Webkit 
  • CVE-2016-4656, Information leak in Kernel 
  • CVE-2016-4657, Kernel Memory corruption leads to Jailbreak.
The issue was found by cyber security firms Lookout and Citizen Lab, who were tipped off to unusual text messages received by an iPhone user in the United Arab Emirates.
Lookout and Citizen Lab worked with Apple on the patch before releasing information on the vulnerability.
The Trident vulnerabilities are exploited in a spyware package called Pegasus which is widely available throughout the world

Leave a Reply

Labels