Apple Users
Related: About this forumApple Confirms New Warning Affecting Almost All iPhone Users
https://www.forbes.com/sites/gordonkelly/2020/04/23/apple-iphone-exploit-vulnerability-ios-13-mail-problem-iphone-11-pro-max-u-iphone-xs-max-xr-update/amp/Apple has already released the best iPhone of 2020, but now millions of iPhone owners both old and new need to be careful because the company has just confirmed a massive iOS security hole which impacts almost every iPhone on the planet.
Following the publication of a devastating report from security firm ZecOps (covered here by Forbes), which claimed that every iPhone running a version of iOS 6 or newer is vulnerable to remote attacks, Apple has now confirmed the problem is real.
So what are we dealing with? What ZecOps discovered is a serious vulnerability in Apples iOS Mail app which allows an attacker to remotely infect an iPhone and gain control over their inbox. In addition, not only did ZecOps find that the attacks can happen without an iPhone owners knowledge but they have been happening for more than two years, with the first attack subsequently detected back in January 2018.
And theres a further kicker: ZecOps found that the attacks are easier to perform on iOS 13 than previous generations of iOS. For example, ZecOps explains that with iOS 12, an attacker requires the iPhone user to open a malicious email. But with iOS 13, it can be triggered unassisted simply from the Mail app being opened in the background.
dweller
(25,043 posts)so deleted it from my iphone
i use a different email so don't miss it
✌🏼
HuskyOffset
(908 posts)That no-click iOS 0-day reported to be under exploit doesnt exist, Apple says
Other critics also question evidence and say 0day may have been confused with simple bug.
https://arstechnica.com/information-technology/2020/04/apple-disputes-report-of-non-click-ios-0day-under-exploit-for-two-years/
Really bad reporting by Forbes. They claim Apple confirmed it, but nowhere in their article, nor in the 9To5Mac article (linked to by the word confirmed in the Forbes article) is there even a hint of Apple confirming the report. Ars Technica is now reporting that Apple is in fact disputing several of ZecOps claims.
WhiteTara
(30,156 posts)for the first time in 10 years and so it's rather comforting to know that I didn't just buy a device that broadcast my info to the world.