Google Finds iMessage Bug That Exposes Files on an iPhone
#1
Quote:A Google security engineer discovered a critical bug in Apple’s iMessage platform that allowed an attacker to obtain access to data stored on an iPhone.
 
Natalie Silvanovich, security researcher and part of the Google Project Zero team, says they discovered a total of five different bugs in iMessage.
All of them have already been reported to Apple and are subject to a 90-day disclosure policy, as per the Project Zero program. According to the researcher, the five issues are the following:
  • CVE-2019-8647 - remote, interactionless use-after-free
  • CVE-2019-8662 - similar to CVE-2019-8647
  • CVE-2019-8660 - remote, interactionless memory corruption
  • CVE-2019-8646 - allows an attacker to read files off a remote device with no user interaction, as user mobile with no sandbox
  • CVE-2019-8641 - still private, as fix not yet available
The iMessage bug, which can be reproduced using the instructions on the page linked above, was reported to Apple back in May. The company included a patch in iOS 12.4, so iPhone users are recommended to install the new software update as soon as possible.

SOURCE: https://news.softpedia.com/news/google-f...6878.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Intel shares Granite Rapids-WS Xeon 600 ...
Intel posts Xeon 6...harlan4096 — 09:49
Manjaro Linux 26.0.3 Build 260228
Manjaro Linux 26.0...harlan4096 — 08:20
K-Lite Codec Pack 19.5.0 / 19.5.4 Update
Changes in 19.5.4 ...harlan4096 — 08:19
JEDEC publishes UFS 5.0 spec with up to ...
KIOXIA starts samp...harlan4096 — 08:17
QOwnNotes
26.2.15  Fix Qt5 ...Kool — 07:30

[-]
Birthdays
Today's Birthdays
avatar (50)daadAmomo
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (51)Claudestync
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>