Skip to main content

Security

See All Stories

Apple updates Platform Security guide with details on iPhone Apple Watch unlock, Touch ID Magic Keyboard

Apple released its 2021 Platform Security guide back in February with new details on M1 Macs, iOS 14, macOS Big Sur, watchOS 7, and more. Now the guide has been updated with specifics on how Touch ID on the new Magic Keyboard works, how iPhone unlock with Apple Watch in iOS 14.5 cryptography works, and more.

Expand Expanding Close

Newly discovered Wi-Fi vulnerabilities affect most devices, but risk is small

Site default logo image

A security researcher with a solid track record in discovering Wi-Fi vulnerabilities has discovered new ones, some of which are part of the core security protocols of the Wi-Fi standard, so are present in virtually every device from 1997 onwards.

The flaws could be exploited to steal sensitive data, control smart home devices, and even take over some computers. There are, however, two pieces of good news. First, the real-life risks for ordinary users are very small. Second, it’s easy to protect yourself against even these small risks …

Expand Expanding Close

Emails reveal 128 million iOS users were affected by ‘XcodeGhost’ malware

iPhone app privacy

You may not remember, but a modified copy of Xcode that surfaced on the web in 2015 was responsible for injecting malware into several iPhone and iPad apps that were subsequently uploaded to the App Store. Now, thanks to the Epic vs. Apple trial, internal Apple emails have revealed that more than 128 million iOS users were affected by the “XcodeGhost” malware.

Expand Expanding Close

China secretly used an award-winning iPhone hack to spy on Uyghur Muslims

Site default logo image

An award-winning iPhone hack was used by the Chinese government to spy on Uyghur Muslims, giving Beijing total control of their phones.

A detailed report says that Chinese white-hat hackers used to participate in the annual Pwn2Own contest designed to uncover and exploit zero-day security vulnerabilities. The hackers win cash prizes, and the issues are reported to the companies concerned so that they can be fixed before details are shared publicly …

Expand Expanding Close

Cellebrite Physical Analyzer has functionality limited with iPhones following Signal blog post

Site default logo image

The Cellebrite Physical Analyzer – the most intrusive phone-cracking tool offered by the company – no longer supports the direct extraction of iPhone data, according to a document shared with us. This follows the discovery and exploitation of a vulnerability by secure messaging app Signal.

Signal discovered multiple security vulnerabilities in Cellebrite’s software, and was able to find a way to booby-trap iPhones to corrupt the results of a scan using Physical Analyzer …

Expand Expanding Close

Location info sold by smartphone apps revealed US military movements in Syria

Site default logo image

US military movements in Syria were revealed by location info available for purchase from smartphone apps, says a new report today. This included enough information to identify the location of an undeclared US military base in the country.

The sensitive location information was harvested from weather, games, and dating apps on the phones of US soldiers, and appears to include special ops personnel …

Expand Expanding Close

AirDrop flaw can easily reveal your phone number and email address to strangers

Site default logo image

An AirDrop flaw means that doing nothing more than opening an iOS or macOS sharing pane within Wi-Fi range of a stranger can enable them to see your phone number and email address. You do not have to initiate an AirDrop transfer to be at risk.

The security researchers who discovered the vulnerability say that they disclosed it to Apple way back in May 2019, but the company still hasn’t provided a fix to the 1.5 billion affected devices …

Expand Expanding Close

Signal uses an iPhone SE to hack Cellebrite phone-cracking software

Cellebrite phone-cracking software hacked by Signal

Secure messaging company Signal has successfully used an iPhone SE to hack Cellebrite‘s phone-cracking software. The company says that anyone could place a file on their iPhone that effectively renders useless any data extraction performed on the phone, and that it will be doing this for Signal users.

Signal says that the file could also compromise all past and future reports generated from the Cellebrite Windows app …

Expand Expanding Close

Senior Apple anti-fraud engineer suggests App Store checks are grossly inadequate

Apple anti-fraud engineer suggests App Store checks do not work

Internal documents released as part of the Epic Games lawsuit reveal an Apple anti-fraud engineer suggesting that App Store checks were grossly inadequate.

Epic cited two particularly damning quotes from Eric Friedman, head of the company’s Fraud Engineering Algorithms and Risk unit, in internal documents …

Expand Expanding Close

Researcher gets $100,000 after finding Safari exploit at Pwn2Own 2021 event

How to use private browsing on Mac with Safari

The Pwn2Own 2021 event is promoted by the Zero Day Initiative as a way to encourage developers and researchers to report zero-day vulnerabilities to the affected companies instead of selling these breaches to malicious hackers. This year, systems researcher Jack Dates was paid $100,000 after finding a new exploit in Apple’s Safari web browser.

Expand Expanding Close

Facebook will tell you if a page is satire, but not if your data was leaked

Site default logo image

Facebook will tell you if a page is satire, as well as if it isn’t, in a new initiative. When a satirical page uses the name of a politician, for example, it will be labeled “Satire Page” to ensure that people don’t mistake it for the real person.

Conversely, posts by politicians will be labeled as “Public Official” …

Expand Expanding Close

Instagram rolling out message restrictions to protect young users

Instagram is taking several steps to make the service safer for its youngest users. Rolling out starting this month, adults won’t be able to send direct messages to teens who don’t follow them. On the flip side, Instagram will give warning alerts to teens before sending messages to adults who have a history of “suspicious behavior.”

Expand Expanding Close

Researchers demonstrate new browser-based side-channel attack that affects Intel and M1 Macs

How to revive and restore M1 Macs

A group of researchers has uncovered what looks to be the first browser-based side-channel attack that’s built entirely from CSS and HTML. The JavaScript-free attack has been found to work across most modern CPUs including Intel, AMD, Samsung, and Apple Silicon. Interestingly, the findings say Apple’s M1 and Samsung’s Exynos chips can sometimes be more susceptible to these novel attacks.

Expand Expanding Close