Active Stocks
Fri Apr 19 2024 12:45:47
  1. Tata Steel share price
  2. 160.45 0.28%
  1. Tata Motors share price
  2. 958.35 -1.34%
  1. NTPC share price
  2. 348.65 -0.78%
  1. Infosys share price
  2. 1,408.55 -0.84%
  1. ITC share price
  2. 424.20 1.25%
Business News/ Technology / News/  Government issues high risk warning for iPhone users: Here’s what they should do
BackBack

Government issues high risk warning for iPhone users: Here’s what they should do

Vulnerabilities in Apple iOS and iPadOS could allow attackers to gain access to sensitive information, execute arbitrary code, or denial of service conditions on iPhones and iPads

CERT-In advisory for iPhones comes with high severity rating.Premium
CERT-In advisory for iPhones comes with high severity rating.

Apple iPhone and iPad users could be at risk. According to an advisory issued by the Indian Computer Emergency Response Team (CERT-In), multiple vulnerabilities have have been reported in Apple iOS and iPadOS that could allow a remote attacker to gain access to sensitive information, execute arbitrary code, spoofing of the interface address or denial of service conditions on the targeted device.

Which Apple devices are impacted?

As per the advisory, Apple iOS 16.1, Apple iOS versions prior to 16.0.3 and iPadOS versions prior to 16 are affected by the vulnerability – CVE-2022-42827. List of impacted devices include Apple iPhone 8 and later, iPad Pro Call models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.

Why does the vulnerability exist in Apple devices?

In its advisory, CERT-In says that these vulnerabilities exist in Apple iOS and iPadOS due to

- Improper security restrictions in AppleMobileFileIntegrity component

- Improper bounds check in Avevideoencoder component; Improper validation in CrNetwork component

- Improper entitlement in Core Bluetooth component

- Improper memory handling in GPU Drivers component

- Memory corruption issue in IOHIDFamily component

- Use after free issue and Race condition issue in IOKit component

- Improper memory handling and Out-of-bounds write issue in Kernel component

- Improper memory handling and Race condition issue in PPP component

- Use after free issue

- Improper security restrictions and Improper path validation in Sandbox component

- Improper UI handling, Type confusion issue and Logic issue in Webkit component

- Use-after-free error in WebKit PDF component

- Improper input validation in Mail component.

How can the vulnerability impact iPhone users?

These vulnerabilities can be exploited by a remote attacker to persuade the victim to open a specially crafted file or application. On successful exploitation of these vulnerabilities, the attacker could gain access to sensitive information, execute arbitrary code, spoofing of the interface address or denial of service conditions on the targeted system.

What should users do?

The CERT-In advisory says that the vulnerability is being exploited in the wild. Users are advised to apply software updates as mentioned in the Apple Security updates.

Unlock a world of Benefits! From insightful newsletters to real-time stock tracking, breaking news and a personalized newsfeed – it's all here, just a click away! Login Now!

Catch all the Technology News and Updates on Live Mint. Download The Mint News App to get Daily Market Updates & Live Business News.
More Less
Published: 26 Oct 2022, 01:40 PM IST
Next Story footLogo
Recommended For You
Switch to the Mint app for fast and personalized news - Get App