Share

Alert over Apple iOS bug

Boston - Researchers have uncovered a bug in Apple's iOS operating system for the iPad and iPhone that makes most devices vulnerable to remote cyber attacks.

Cybersecurity firm FireEye Inc published details about the vulnerability on its blog on Monday, saying the bug enables hackers to access their devices by persuading users to install malicious applications with tainted text messages, emails and web links.

The malicious application can then be used to replace genuine, trusted apps that were installed through Apple's App Store, including email and banking programs, with malicious software through a technique that FireEye has dubbed "Masque Attack."

These attacks can be used to steal banking and email login credentials or other sensitive data, according to FireEye, which is well-regarded in cybersecurity circles for its research.

"It is a very powerful vulnerability and it is easy to exploit," FireEye Senior Staff Research Scientist Tao Wei said in an interview.

Officials with Apple could not be reached for comment.

Wei said that FireEye disclosed the vulnerability to Apple in July and that representatives with the company have said they were working to fix the bug.

News of the vulnerability began to leak out in October on specialized web forums where security experts and hackers alike discuss information on Apple bugs, Wei said.

Wei said that FireEye decided to go public with its findings after Palo Alto Networks Inc last week uncovered the first campaign to exploit the vulnerability, a new family of malicious software known as WireLurker that infects both Mac computers and iOS.

FireEye does not know of other attacks that exploit the bug, Wei said.

"Currently WireLurker is the only one, but we will see more," he said.

FireEye advises iOS users to refrain from install apps from sources other than Apple's official App Store and to not click "install" on a pop-up from a third-party web page.

The security firm said it verified this vulnerability on iOS 7.1.1, 7.1.2, 8.0, 8.1 and 8.1.1 beta, for both jailbroken and non-jailbroken devices.



We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
18.82
+1.1%
Rand - Pound
23.53
+1.1%
Rand - Euro
20.16
+1.2%
Rand - Aus dollar
12.31
+0.7%
Rand - Yen
0.12
+1.8%
Platinum
922.30
-0.4%
Palladium
964.50
-2.6%
Gold
2,345.52
+0.6%
Silver
27.58
+0.5%
Brent Crude
89.01
+1.1%
Top 40
69,438
+1.5%
All Share
75,393
+1.4%
Resource 10
63,106
+1.6%
Industrial 25
103,764
+1.2%
Financial 15
16,076
+1.7%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders