Audio By Carbonatix
A team of bug-hunters at Google have shared details of five flaws in Apple's iMessage software that could make its devices vulnerable to attack.
In one case, the researchers said the vulnerability was so severe that the only way to rescue a targeted iPhone would be to delete all the data off it.
Another example, they said, could be used to copy files off a device without requiring the owner to do anything to aid the hack.
Apple released fixes last week.
But the researchers said they had also flagged a sixth problem to Apple, which had not been rectified in the update to its mobile operating system.
"That's quite unusual," commented Prof Alan Woodward, a cyber-security expert at the University of Surrey.
"The reputation of the Google Zero team is such that it is worth taking notice of."
The Project Zero team was established in July 2014 to uncover previously undocumented cyber-vulnerabilities. It has previously alerted Microsoft, Facebook and Samsung, among others, to problems with their code.
Urgent update
Apple's own notes about iOS 12.4 indicate that the unfixed flaw could give hackers a means to crash an app or execute commands of their own on recent iPhones, iPads and iPod Touches if they were able to discover it. Apple has not commented on this specific issue, but has urged users to install the new version of iOS, which addresses Google's other discoveries as well as a further range of glitches and threats. "Keeping your software up to date is one of the most important things you can do to maintain your Apple product's security," it said in a statement. News site ZDnet - which was first to report the matter - noted that the level of detail shared by Google about the other bugs could be enough to let bad actors craft exploits to take advantage of them. Users should download iOS 12.4 "with no further delay," it added. One of the two Google researchers involved - Natalie Silvanovich - intends to share more details of her findings at a presentation at the Black Hat conference in Las Vegas next month. The synopsis of her talk also promises it will cover potential vulnerabilities in Apple's Visual Voicemail service - which allows users to select specific recordings - and its Mail app. One of Apple's own security chiefs will also be attending the conference to give a separate presentation, which promises to go "behind the scenes of iOS and Mac security".DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Latest Stories
-
Kpebu doubts claims that Akufo-Addo administration interfered with Special Prosecutor
1 hour -
It’s difficult to believe everything the OSP says – Manasseh Awuni
1 hour -
I would’ve blocked Ofori-Atta from leaving Ghana if I were Special Prosecutor – Martin Kpebu
2 hours -
I’m headed for public office, but not the OSP role – Martin Kpebu
2 hours -
I will only submit my allegations to a board, not the OSP’s subordinates – Martin Kpebu
3 hours -
‘I’m still a bit traumatised’ – Martin Kpebu recounts alleged abuse during OSP arrest
3 hours -
Martin Kpebu dismisses claims he seeks to become Special Prosecutor
3 hours -
Martin Kpebu denies verbally abusing OSP officers, says allegations are fabricated
3 hours -
Mahama arrives in Doha for 2025 Doha Forum engagements
3 hours -
Milo U13 Champs: Ahafo’s Adrobaa set for thrilling final with Franko International of Western North
5 hours -
Ghana’s HIV crisis: Stigma drives new infections as AIDS Commission bets on AI and six-month injectables
7 hours -
First Ladies unite in Accra to champion elimination of mother-to-child HIV, Syphilis, and Hepatitis B transmission
7 hours -
US Supreme Court agrees to hear case challenging birthright citizenship
8 hours -
Notorious Ashaiman robber arrested in joint police operation
9 hours -
Judge sets key dates after video evidence hurdle in Nana Agradaa appeal case
9 hours
