Apple on Monday released a new version of the iPhone and iPad’s operating systems to fix a vulnerability that hackers were exploiting in the wild, meaning they were taking advantage of it to hack Apple devices.
On the security update page, Apple wrote that it “is aware of a report that this issue may have been actively exploited.” This is the language Apple uses when someone alerts the company that they have observed hackers exploiting a bug against targets in the real world, as opposed to a vulnerability found by a researcher in a controlled environment, so to speak.
In this case, Apple credited an anonymous researcher for the discovery, and also thanked Citizen Lab “for their assistance.” Citizen Lab is a digital rights research group housed at the University of Toronto’s Munk School, known for exposing the abuse of government hacking tools such as those made by NSO Group.
Apple’s spokesperson Scott Radcliffe told TechCrunch that the company has nothing to add apart from what’s in the release notes. Bill Marczak, a senior researcher at Citizen Lab, said that he and his colleagues have no comments for now.
This latest bug was in WebKit, Apple’s browser engine that’s used in Safari, and a historically popular target for hackers, since it can open up access to the rest of the device’s data.
In 2021, Motherboard reported that in just the first four months of that year, Apple had patched seven bugs exploited in the wild, of which six were in WebKit, a number that experts considered high at the time.
Since then, things have improved. According to TechCrunch’s count of vulnerabilities, since January 2022, there have been nine bugs in iOS that “may have been actively exploited,” of which four in WebKit. The others were three in the kernel, the core component of the operating system; one in AppleAVD, the company’s audio and video decoding framework; and one in IOMobileFrameBuffer, a kernel extension.
As usual, the chances that an average iPhone user will be targeted with a zero-day like this one are slim, but you should still update your phone.
Cloud computing giant Rackspace has confirmed hackers accessed customer data during last month’s ransomware attack. The attack, which Rackspace first confirmed on December 6, impacted the company’s hosted Exchange email environment, forcing the web giant to shut down the hosted email service following the incident. At the time, Rackspace said it was unaware “what, if […]
The Housing Authority of the City of Los Angeles, or HACLA, has confirmed it is investigating a cybersecurity incident shortly after the LockBit ransomware gang claimed responsibility for a cyberattack on the agency. HACLA, which provides affordable housing to more than 19,000 low-income families across Los Angeles, was added to LockBit’s dark web leak site on […]
A recent study finds that software engineers who use code-generating AI systems are more likely to cause security vulnerabilities in the apps they develop. The paper, co-authored by a team of researchers affiliated with Stanford, highlights the potential pitfalls of code-generating systems as vendors like GitHub start marketing them in earnest. “Code-generating systems are currently […]
Leave a Reply