What’s Going on With Apple’s iOS Security Flaws?

Apple is usually known for how much it values user privacy, and the lengths it goes to secure their data. Which is why pretty much everyone was surprised to hear that iOS actually had some serious vulnerabilities which hackers could have easily exploited.

If this is the first time you’re hearing about this, we’ll tell you all you need to know about these security flaws. We’ll also show you how to update to the latest version to make sure you stay safe, and offer some extra security tips too.

What Were the Security Flaws in Question?

A few anonymous security researchers found the issues and notified Apple about them. The spotlight is on three security vulnerabilities: two with WebKit and one with the OS kernel.

The WebKit Issues

This is the main component of Safari. In short, WebKit is an open-source web browser engine.

The two security flaws would have allowed a hacker to remotely execute arbitrary code. That basically means they would have been able to run any commands they wanted. So they could have easily taken over Safari – as well as any other apps that use WebKit!

What does that mean for you?

There are tons of possible scenarios. For example, a cybercriminal could have forced Safari to send your traffic to a phishing site (a fake copy of PayPal, for instance).

The OS Kernel Issue

The kernel is the central part of the operating system. If a hacker exploits it, they get access to the entire OS.

Well, this particular vulnerability would have made it possible for a hacker to use a malicious app to gain elevated privileges. That would have made it easy for them to get access to tons of your private data.

That’s not All!

Those three problems were the highlight, but they weren’t the only vulnerabilities. There were actually a lot of bugs with Bluetooth, CoreAudio, CoreText, CoreGraphics, ImageIO, and more that cybercriminals could have exploited to trigger arbitrary code execution or DoS attacks.

To see the whole list of security flaws, check out this support article from Apple.

Did Apple Fix the iOS Security Flaws?

Yes, they were quick to act. The new update (14.4) fixes all these problems. So be sure to update to the new version!

If you don’t know how, just do this:

  1. Go to Settings, and pick General.
  2. Tap Software Update.
  3. Next, tap Download and Install.
  4. That’s it – just wait for the update to finish.

And while you’re at it, make sure to turn on automatic updates. That way, you won’t have to worry about accidentally skipping an important security update.

Two More Security Tools to Use to Stay Safe

While Apple fixed the security issues, that doesn’t mean you shouldn’t take extra measures (other than updating to 14.4). To make sure you’re always safe online and offline, you should also use:

  • VPNs – They can protect your from traffic eavesdropping and MITM attacks that take you to phishing sites by encrypting your data. VPNs also hide your digital footprints by masking your IP. To find the best services, we recommend checking out ProPrivacy’s list of iPhone VPNs.
  • Antivirus programs–These security tools are an excellent line of defense against malware infections. Plus, they can also block connections to malicious sites. In our opinion, Malwarebytes is an excellent iPhone antivirus.

The Bottom Line

Apple’s iOS suffered some serious vulnerabilities, which it luckily fixed with the new version: 14.4. Be sure to update to it ASAP.

If you have any other relevant information to share with us about this topic, please do so in the comments.

Balaji N

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago