Apple is Killing the iPhone’s Silent Switch

The ring/silent switch has been on the iPhone since the very first one was announced in 2007 by Steve Jobs, but now the writing is on the wall for the device’s last significant moving part. From a report: With its replacement by a haptic “action button…

September 13, 2023
Read More >>

Zero-Click Exploit in iPhones

Make sure you update your iPhones:

Citizen Lab says two zero-days fixed by Apple today in emergency security updates were actively abused as part of a zero-click exploit chain (dubbed BLASTPASS) to deploy NSO Group’s Pegasus commercial spyware onto fully patched iPhones.

The two bugs, tracked as CVE-2023-41064 and CVE-2023-41061, allowed the attackers to infect a fully-patched iPhone running iOS 16.6 and belonging to a Washington DC-based civil society organization via PassKit attachments containing malicious images.

“We refer to the exploit chain as BLASTPASS. The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab …

September 13, 2023
Read More >>

Apple Announces iPhone 15 with USB-C

Apple has just announced the iPhone 15 and 15 Plus, and the big news is a USB-C port. From a report: We’ve been waiting for the day that the iPhone would switch to the widely used USB-C standard instead of Apple’s proprietary Lightning connector. Apple…

September 12, 2023
Read More >>

CISA adds recently discovered Apple zero-days to Known Exploited Vulnerabilities Catalog

U.S. CISA adds vulnerabilities in Apple devices exploited to install NSO Group’s Pegasus spyware on iPhones to Known Exploited Vulnerabilities Catalog US Cybersecurity and Infrastructure Security Agency (CISA) added the security vulnerabilities chained in the zero-click iMessage exploit BLASTPASS to its Known Exploited Vulnerabilities Catalog. The two flaws, tracked as CVE-2023-41064 and CVE-2023-41061, were used to install NSO […]

The post CISA adds recently discovered Apple zero-days to Known Exploited Vulnerabilities Catalog appeared first on Security Affairs.

September 11, 2023
Read More >>

Apple discloses 2 new actively exploited zero-day flaws in iPhones, Macs

Apple rolled out emergency security updates to address two new actively exploited zero-day vulnerabilities impacting iPhones and Macs. The two Apple zero-day vulnerabilities, tracked as CVE-2023-41064 and CVE-2023-41061, reside in the Image I/O and Wallet frameworks. CVE-2023-41064 is a buffer overflow issue that was reported by researchers from researchers at Citizen Lab. The IT giant […]

The post Apple discloses 2 new actively exploited zero-day flaws in iPhones, Macs appeared first on Security Affairs.

September 7, 2023
Read More >>