Update your Apple devices now! Two major security vulnerabilities in Apple were exposed, allowing spyware to be implanted without interaction
Xiao Xiao comes from Ao Fei
Temple Qubit | Official account QbitAI
Don’t hesitate to update your Apple devices now!
Just in the past two days, a security organization discovered two latest vulnerabilities in Apple devices, affecting tablets, mobile phones, computers, etc .——
For example, iPhones equipped with iOS 16.6 version, as well as new versions of iPad tablets, Mac computers and Apple Watches, etc.
By exploiting these vulnerabilities, hackers can turn on your microphone to record conversations, and steal your data quietly while you are charging, ensuring that power consumption is not discovered.
The entire process does not require any user interaction , such as downloading an APP or clicking on an email.
At present, Apple has officially released repair versions of these two vulnerabilities, which can be installed with a click.
So, what is going on with these two vulnerabilities?
Can be attacked without interaction
These two vulnerabilities are zero-day vulnerabilities that have been exploited by hackers before they were officially discovered by Apple .
Researchers at Citizen Lab at the University of Toronto in Canada discovered the two vulnerabilities, which hackers had exploited to plant spyware called Pegasus on an iPhone device.
This software can not only steal private information such as photos, but also quietly turn on the microphone and record conversations, and even track actions and record texts.
Although some malware can be discovered through significantly increased battery consumption of mobile phones or APPs from unknown sources, Pegasus is more "smart" and can choose to quietly collect data at night or while charging.
(According to Business Insider, when Amazon CEO Bezos revealed his extramarital affair, it seems that hackers used Pegasus to "hack" his phone and expose device data.)
However, these two vulnerabilities are more serious because they can be directly implanted into iPhones with the latest version of iOS without even requiring user interaction .
The two vulnerabilities are named CVE-2023-41064 and CVE-2023-41061 respectively.
CVE-2023-41064 involves Apple's Image I/O framework, affecting iPhones, iPads, Mac computers, and Apple Watches. When the device processes "maliciously crafted images," it may be vulnerable.
CVE-2023-41061 appears in the Apple Wallet feature, causing security issues whenever the device receives a "maliciously crafted attachment."
Currently, Apple has fixed these two vulnerabilities in a timely manner and released an updated version.
It is recommended to update and enable "Lockdown Mode"
The fix patch is placed in the version updates of each system, including version 13.5.2 of macOS, version 16.6.1 of iOS and iPadOS, and version 9.6.2 of watchOS.
Now, you can already receive update reminders on Apple devices such as Mac and iPhone.
It is worth noting that these two vulnerabilities are not part of Apple's Rapid Security Response (Rapid Security Response), which is a patch that can be updated and removed at any time.
In contrast, it is added to regular system updates and cannot be rolled back to the previous version after installation.
At the same time, Apple also gives suggestions to turn on the lock mode if necessary , which can effectively prevent attacks by such vulnerabilities.
Lockdown mode is a protection mode "designed for a very small number of Apple users" launched by Apple in iOS, iPadOS 16 and macOS Ventura. These users are often targeted by hackers for work and other reasons.
After turning it on, users will be strictly restricted in using certain apps, browsing websites and functions on Apple devices to ensure device security:
However, netizens have different views on the suggestion of locking mode.
Some netizens believe that the lock-down mode should no longer limit the target audience, and it is best for everyone to use it :
Not only does it reduce unnecessary background operations, it also saves battery power.
However, some netizens believe that it is really inconvenient to use some functions after turning on the lock mode, such as slowing down the loading speed of web pages :
Ordinary users are not at that high risk of being attacked. Apple might as well create a third mode that allows users to choose "security" or "performance" when it comes to security protection that reduces performance.
Have you ever used Apple's Lockdown Mode? How does it feel?
Reference links:
[1]https://therecord.media/apple-discloses-two-zero-days-in-new-updates
[2]https://citizenlab.ca/2023/09/blastpass-nso-group- iphone-zero-click-zero-day-exploit-captured-in-the-wild/
-over-
"Quantum Think Tank·Large Model Talent Salon" is recruiting
"Quantum Think Tank·Large Model Talent Salon" will be held in Zhongguancun, Beijing, in late September. Players from all fields of large model are welcome to participate~
Click on the picture for details. To register, companies can contact the event leader Wang Linyu (WeChat: iris_wang17, please note company + name).
The salon audience channel will be opened later, so stay tuned~
Click here ???? Follow me and remember to star~
Featured Posts