Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

WhiteTara

(29,704 posts)
Sat Apr 25, 2020, 01:59 AM Apr 2020

Apple Confirms New Warning Affecting Almost All iPhone Users

https://www.forbes.com/sites/gordonkelly/2020/04/23/apple-iphone-exploit-vulnerability-ios-13-mail-problem-iphone-11-pro-max-u-iphone-xs-max-xr-update/amp/

Apple has already released the best iPhone of 2020, but now millions of iPhone owners – both old and new – need to be careful because the company has just confirmed a massive iOS security hole which impacts almost every iPhone on the planet.

Following the publication of a devastating report from security firm ZecOps (covered here by Forbes), which claimed that every iPhone running a version of iOS 6 or newer is vulnerable to remote attacks, Apple has now confirmed the problem is real.

So what are we dealing with? What ZecOps discovered is a serious vulnerability in Apple’s iOS Mail app which allows an attacker to remotely infect an iPhone and gain control over their inbox. In addition, not only did ZecOps find that the attacks can happen without an iPhone owner’s knowledge but they have been happening for more than two years, with the first attack subsequently detected back in January 2018.

And there’s a further kicker: ZecOps found that the attacks are easier to perform on iOS 13 than previous generations of iOS. For example, ZecOps explains that with iOS 12, an attacker requires the iPhone user to open a malicious email. But with iOS 13, it can be triggered unassisted simply from the Mail app being opened in the background.
3 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Apple Confirms New Warning Affecting Almost All iPhone Users (Original Post) WhiteTara Apr 2020 OP
i never use that app dweller Apr 2020 #1
Incorrect HuskyOffset Apr 2020 #2
Thanks. I just bought a phone WhiteTara Apr 2020 #3

HuskyOffset

(888 posts)
2. Incorrect
Sat Apr 25, 2020, 05:21 AM
Apr 2020

“That no-click iOS 0-day reported to be under exploit doesn’t exist, Apple says
Other critics also question evidence and say 0day may have been confused with simple bug.”

https://arstechnica.com/information-technology/2020/04/apple-disputes-report-of-non-click-ios-0day-under-exploit-for-two-years/

Really bad reporting by Forbes. They claim Apple confirmed it, but nowhere in their article, nor in the 9To5Mac article (linked to by the word “confirmed” in the Forbes article) is there even a hint of Apple confirming the report. Ars Technica is now reporting that Apple is in fact disputing several of ZecOps’ claims.

WhiteTara

(29,704 posts)
3. Thanks. I just bought a phone
Sat Apr 25, 2020, 10:24 AM
Apr 2020

for the first time in 10 years and so it's rather comforting to know that I didn't just buy a device that broadcast my info to the world.

Latest Discussions»Culture Forums»Apple Users»Apple Confirms New Warnin...