Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts

02 September 2025

Apple Patches Zero-Day Flaw that Targeted Users

Someday security will be a thing, but it is not today. From Bleeping Computer: Apple fixes new zero-day flaw exploited in targeted attacks

Apple has released emergency updates to patch another zero-day vulnerability that was exploited in an "extremely sophisticated attack."

The exploit, an out of bounds write, which apparently could lead to remote code execution was fixed by "improved bounds checking." It is Apple, so they say very little, or nothing at all

They have patches to apply, but they haven't said you need to do a full reset and reload of updates.

This impacts iPhones, iPads, and Macs. Click thru for the list of exactly what is impacted.

While this flaw is likely only exploited in highly targeted attacks, it is strongly advised to install today's security updates promptly to prevent any potential ongoing attacks.

With this vulnerability, Apple has fixed a total of six zero-days exploited in the wild since the start of the year.

Not the only issue. Also from Bleeping Computer: WhatsApp patches vulnerability exploited in zero-day attacks

This was apparently linked to the previous exploit in some way.

When Apple released emergency updates to patch the CVE-2025-43300 zero-day flaw earlier this month, it also stated that the flaw had been exploited in an "extremely sophisticated attack."

While the two companies are yet to publish further information regarding the attacks, Donncha Ó Cearbhaill (the head of the Security Lab at Amnesty International) said that WhatsApp just warned some users that they've been targeted in an advanced spyware campaign over the last 90 days.

In this case, WhatsApp is recommending you do a system reset to make sure that the exploit doesn't survive a security update and reboot. The good news, if there is any, is that WhatsApp was able to identify who was targeted and give them specific warnings and instructions for mitigation.

In the threat notifications sent to potentially impacted individuals, WhatsApp advises them to perform a device factory reset and to keep their devices' operating system and software up to date.

In the words of Sgt. Phil Esterhaus, from the Polish Hill Station: "Let's be careful out there." The internet is a dangerous place.

02 May 2025

Court Takes a Battering Ram to Apple's Walled Garden

I'm not a fan of Apple and their walled garden. They have some decent tech, which is too expensive, and they have some questionable software, but they have a few awful business practices. They got pulled up short on some of those business practices on Wednesday, April 30th.

Apple's anticompetitive behavior included (mostly) their 30% tax on every transaction carried out through any app on the phone. Epic Games (the folks behind Fortnite) defied them and were banned, they took Apple to court. Epic even redid the old Apple 1984 commercial. (For those of you too young to remember the 1984 Apple v IBM commercial, it is linked at the bottom.)

And yes, this is mostly Schadenfreude.

"You Either Die A Hero, Or You Live Long Enough To See Yourself Become The Villain." Apple went from the plucky underdog in 1984 to the villain in 2020.

Yesterday the judge in the case - which was supposed to have been decided in 2021 - told Apple to stop screwing around, and referred them on a Contempt of Court Charge to the DOJ.

From Tech Crunch we get a summary of the ruling: Read the juiciest bits from the Apple-Epic court ruling

That article hits all the highlights.

Judge Yvonne Gonzalez Rogers is pissed off at Apple. Really, really pissed off.

In Rogers’ newly released 80-page decision, she took Apple and its executives to task for defying the court’s orders in its original case with Fortnite maker Epic Games. Though Apple largely won that round, as it was determined the tech giant was not a monopolist, the court decided that Apple was behaving in an anticompetitive fashion in one specific area: by not allowing app developers to offer their customers other ways to pay outside of Apple’s own payment platform.

The entire 80 page ruling can be found at this link: Case No. 4:20-cv-05640-YGR
ORDER GRANTING EPIC GAMES, INC.’S MOTION TO ENFORCE INJUNCTION;
DENYING APPLE INC.’S MOTION TO SET ASIDE JUDGMENT;
DENYING APPLE INC.’S MOTION UNDER FEDERAL RULE OF EVIDENCE 502(D);
DENYING APPLE INC.’S MOTION FOR ENTRY OF JUDGMENT ON ITS INDEMNIFICATION COUNTERCLAIM WITHOUT PREJUDICE; AND
REFERRAL TO THE UNITED STATES ATTORNEY RE CRIMINAL CONTEMPT

I. OVERVIEW
For the reasons set forth herein, the Court FINDS Apple in willful violation of this Court’s 2021 Injunction which issued to restrain and prohibit Apple’s anticompetitive conduct and anticompetitive pricing. Apple’s continued attempts to interfere with competition will not be tolerated.

The hat tip for all of this goes to Mutahar at Some Ordinary Gamers and his video Apple Just Got Completely Destroyed In Court....

For the youngsters, here is the Apple 1984 commercial introducing the Macintosh.

And just because... "Another Brick In The Wall (Part 1)" by Pink Floyd

06 April 2025

Which Is Why Monopolies Need to Be Busted

Not that I expect it to happen anything soon. Epic Games CEO calls Apple and Google 'gangster-style' businesses in need of competition | TechCrunch

The company [Epic Games] sued both Apple and Google for monopolistic practices over their respective app stores. Epic won its case with Google but not with Apple. However, the court did require Apple to open up to more competition by forcing a change to its App Store rules. The court said app developers should now be able to link to other purchasing mechanisms besides Apple’s own. (Unfortunately for app developers, Epic is still battling with Apple in the courts over this change, as it alleges that Apple violated the court order by allowing developers to process their own payments, but only with a small, 3% reduction in commission, which doesn’t make it worth their while.)

Click thru for the rest.

Basically they will ignore the law for as long as they can.

15 January 2024

Apple's Hardware Backdoor into the iPhone

The moral of the story is that secrets will get out. Researchers Uncover the ‘Most Sophisticated’ iPhone Exploit Ever

What happens when you hack a cybersecurity researcher? Kaspersky, a Moscow-based security firm, presented new details regarding zero-day vulnerabilities in Apple products on Wednesday [27 December]. Kaspersky researchers are calling this the most sophisticated attack they’ve ever seen, exposing a previously unknown hardware feature.

Apple put a secret hardware backdoor into the past few generations of the iPhone. Confident that they could keep the secret of its existence secret. But some people knew, and it is a secret worth a million dollars via places like Zerodium. Maybe millions of dollars. Secrets don't get kept under those circumstances. Apple found that out.

“This is no ordinary vulnerability,” said Kaspersky’s Boris Larin in a research paper Wednesday. “What we do know—and what this vulnerability demonstrates—is that advanced hardware-based protections are useless in the face of a sophisticated attacker as long as there are hardware features that can bypass those protections.”

The articles in the mainstream tech press are not very useful or informative. If you have the time, and are interested in a deep dive into what this is, how the backdoor worked, etc. I recomend Steve Gibson's analysis from "SECURITY NOW 955: THE MYSTERY OF CVE-2023-38606." It is a two hour video, though the bit on Apple, Kaspersky, and this hardware back door starts at 34 minutes and 40 seconds.

Kaspersky’s researchers affirmatively and without question found a deliberately concealed, never documented, deliberately locked but unlockable with a secret hash, hardware backdoor which was designed into all Apple devices starting with the A12, A13, A14, A15 and A16. [Ref. SN #955 Show Notes]

Kaspersky called this "the most sophisticated attack ever discovered against Apple devices."

28 December 2023

Apple and Their Continued Reliance on Security Through Obscurity

If we have learned anything in the past 20 years, it is that security through obscurity does NOT work. Apple refuses to believe that. iPhone Triangulation attack abused undocumented hardware feature

Operation Triangulation is the name given to a spyware attack discovered in June by Kaspersky Labs.

The discovery and use of obscure hardware features likely reserved for debugging and factory testing to launch spyware attacks against iPhone users suggest that a sophisticated threat actor conducted the campaign.

Moreover, it constitutes an excellent example of why reliance on security through obscurity and the secrecy of hardware design or hardware testing implementation is a false premise.

The exploit is a zero-click attack that starts with sending a maliciously crafted iMessage to the target phone. That iMessage doesn't need to be opened and it leaves no trace.

It is fairly technical, but it relied on using undocumented hardware features to bypass Apple's hardware protection system. Leaving the unknown features in place was either a mistake or done to facilitate testing.

Apple in its continuing reliance on obscurity, didn't say much, they just issued an emergency patch in June.

16 October 2023

Apple Doesn't Care If You Are Being Stalked

Apple: Wouldn't it be great if you could find something no matter where it got to?

Stalkers everywhere: Why yes it would, actually.

And so we have this. Apple AirTags stalking led to ruin and murders, lawsuit says | Ars Technica

This month, more than three dozen victims allegedly terrorized by stalkers using Apple AirTags have joined a class-action lawsuit filed in a California court last December against Apple. They alleged in an amended complaint that, partly due to Apple's negligence, AirTags have become "one of the most dangerous and frightening technologies employed by stalkers" because they can be easily, cheaply, and covertly used to determine "real-time location information to track victims."

Apple hasn't done enough to "mitigate harms," according to the lawsuit.

You can click thru for some of the experiences of people being stalked.

The real issue is that Apple doesn't give a damn because they are making money.

Both tech and domestic violence experts warned Apple ahead of the product release that AirTags could be used for unwanted stalking, but instead of making AirTags safer, the complaint alleged that Apple instead "dangerously rushed" AirTags "to market." Eva Galperin, the director of cybersecurity at the Electronic Frontier Foundation, in a report quoted in the complaint, called AirTags "uniquely harmful" when they were first released.

"Apple automatically turned every iOS device into part of the network that AirTags use to report the location of an AirTag," Galperin said. "The network that Apple has access to is larger and more powerful than that used by the other trackers. It’s more powerful for tracking and more dangerous for stalking.”

I don't expect that the .gov will force Apple to do anything, not even pay a meaningful fine.

07 June 2023

I'm Shocked - Shocked I Tell You! - To Learn that Spies Spy

Yeah, OK... Not shocked. Not even a little. Russia blames US and Apple for hacking diplomat iPhones

I will say up front that this doesn't sound like Apple; they don't usually help people outside of China. It does sound like various spy organizations, however. I mean, aren't they SUPPOSED to spy on our enemies?

Russia has accused Apple and US intelligence agencies of collaborating to spy on its diplomats by hacking their iPhones.

And really, Apple wouldn't have to be involved, outside of their creating non-secure software. (And no matter what the fanbois say, it is NOT secure.)

Back when COVID was just getting rolling, and the lockdowns were starting, hackers had a lot of time on their hands, and came up with a boatload of Apple iOS hacks. Zerodium - the people who pay big bucks for this kind of thing - announced shortly into the lockdown that they were no longer paying for zero-click iPhone hacks. They had too many at the time. I haven't looked to see if they have started collecting those hacks again, but I would guess that they have, since a fair few of them have been patched by Apple. (See iOS security is f**ked from 2020.)

My point is, the NSA/CIA/EIEIO would not have to get Apple involved; they would only need to buy access from Zerodium (if you assume that the NSA is NOT Zerodium), or someone else. And it isn't like the NSA doesn't have their own staff of hackers. Or so I assume.

A spokesperson for Kaspersky told The Record that “due to the absence of technical details reported," the security company couldn't confirm all the findings from the FSB.

The FSB is basically Russia's version of the FBI. And yes I know they used to be the KGB; I stand by that characterization of the FBI. The FSB is who is actually making all of the accusations.

Anyway, the Russians are pissed that they were being spied on. (Does this mean we knew about the Ukraine invasion in advance?) Here's a tiny violin to express my feelings of sympathy. Or not, as the case may be.

The hat tip for all of this goes to Shannon Morse at ThreatWire and the video Amazon FINED For Privacy Violations - ThreatWire. I have it queued up the section on the Russian hack.The story about Amazon is the last story in Tuesday's episode of ThreatWire, so if you're interested in the small fines being levied against Amazon. ($55 million in fines? That's a joke. Meta/F*c*book was fined €1.2 billion in May for mishandling data.)

15 November 2022

Apple - Not So Privacy Minded After All

They want you to believe that you have privacy. Apple Sued Over iPhone Privacy Settings After Gizmodo Story

The problem was spotted by two independent researchers at the software company Mysk, who found that the Apple App Store sends the company exhaustive information about nearly everything a user does in the app, despite a privacy setting, iPhone Analytics, which claims to “disable the sharing of Device Analytics altogether” when switched off. Gizmodo asked the researchers to run additional tests on other iPhone apps, including Apple Music, Apple TV, Books, and Stocks. The researchers found that the problem persists across most of Apple’s suite of built-in iPhone apps.

The article linked above is mostly about the lawsuit, and the fact that Apple seems to be in violation of California privacy law. If you want more of the details about what Apple is actually doing, that information can be found at the following link: Apple Is Tracking You Even When Its Own Privacy Settings Say It’s Not, New Research Says.

For all of Apple’s talk about how private your iPhone is, the company vacuums up a lot of data about you. iPhones do have a privacy setting that is supposed to turn off that tracking. According to a new report by independent researchers, though, Apple collects extremely detailed information on you with its own apps even when you turn off tracking.

Privacy is such a 20th Century concept.

27 September 2021

It's more what you'd call guidelines than actual rules

If Apple doesn't enforce the rules around privacy and tracking, are they really rules? When you ‘Ask app not to track,’ some iPhone apps keep snooping anyway

Apple made a big splash about their privacy advocacy, and their rules about blocking tracking via the iPhone. There is just a small problem. If you tell apps not to track you, some apps just ignore that request and track you anyway.

But something curious happens after you ask not to be tracked, according to an investigation by researchers at privacy software maker Lockdown and The Washington Post. Subway Surfers starts sending an outside ad company called Chartboost 29 very specific data points about your iPhone, including your Internet address, your free storage, your current volume level (to 3 decimal points) and even your battery level (to 15 decimal points). It’s the kind of unique data that could be used by advertisers to identify your iPhone, possibly letting them know what other apps you use or how to target you.

In other words, it’s sidestepping your request to be left alone. You can’t stop it. And your privacy is worse off for it.

So apparently Apple doesn't see fingerprinting as tracking. Even though everyone else in the universe does. What is the other choice? That they don't care, or that they are flat out lying about privacy?

Click thru for the rest of the info. How Apple was made aware of the tracking going on in some cases, and have done nothing, even though weeks have gone by. They could block the offending apps from their app-store in short order, if they cared.

So is Apple's advertising just that? Is it empty words? (Hat tip to Input Magazine.)

The title to this post is a misquote from Pirates of the Caribbean: The Curse of the Black Pearl.

26 September 2021

How Much Does Apple Care About Your Security?

They claim to love security and privacy. So it is hard to see how this situation came to pass. They wouldn't be lying to everyone, now would they? Researcher drops three iOS zero-days that Apple refused to fix

The researcher has followed responsible disclosure. He waited 6 months - double the 90 days Google Project Zero uses as a benchmark - in the case of one of the bugs. Apple did fix one bug that he notified them of, but without mentioning it and without paying for it.

Click thru for the details on these 3 zero-days. But there is one thing that really caught my attention.

It seems that this is not one-off occurance, but that Apple has a tendency to NOT live up to the terms of its published bug-bounty.

Other security researchers and bug bounty hunters have also gone through a similar experience when reporting vulnerabilities to Apple's product security team via the Apple Security Bounty Program.

Just this year, some of them have reported that they weren't paid the amount listed on the official bounty page [1, 2] or haven't received any payment at all, others that they have been kept in the dark for months on end with no replies to their messages.

Others have also said their bugs were silently fixed with Apple refusing to give them credit, just as it happened in this case.

It isn't because they can't afford it. So it must be because they don't want to pay.

And as for Apple's "we care deeply about your privacy" statements.

"All this information is being collected by Apple for unknown purposes, which is quite disturbing, especially the fact that medical information is being collected," the researcher said, referring to the analyticsd zero-day silently patched in iOS 14.7.

"That's why it's very hypocritical of Apple to claim that they deeply care about privacy. All this data was being collected and available to an attacker even if 'Share analytics' was turned off in settings.

Some of these vulnerabilities are probably not of interest to folks like Zerodium, but some probably are, and while I don't like the idea of feeding the beast, I completely understand the "if you're going to screw me over then all bets are off" point-of-view. I wonder if Apple understands that?

The Register had even harsher things to say. Frustrated dev drops three zero-day vulns affecting Apple iOS 15 after six-month wait

"To me, the bigger takeaway is that Apple is shipping iOS with known bugs," [Patrick Wardle, founder of free security project Objective See and director of research at security biz Synack] continued, noting that IllusionOfChaos claims to have reported the bugs months ago. "And that security researchers are so frustrated by the Apple Bug Bounty program they are literally giving up on it, turning down (potential) money, to post free bugs online."

Wardle said he considered the researcher's critique of Apple's Security Bounty program to be fair.

"It's not that Apple doesn't have resources or money to fix this," he said. "Clearly it's just not a priority to them. "

And why should it be. If your iPhone gets hacked, what does it cost Apple? 15 minutes of egg on their faces? Maybe. But you agreed to the terms and conditions when you opened the shrink-wrap on your new iPhone, and those terms say that they aren't responsible for anything. (The same goes for Microsoft and Windows. Bugs don't cost them anything. But that is a story for another day.) Are you going to quit using your iPhone because of any of this?

The Register asked Apple to comment, but the brick wall did not respond.

Heh.

11 May 2021

Apple: If we ignore the problem, maybe it will go away

Because that is how executives think. Apple brass discussed disclosing 128-million iPhone hack, then decided not to | Ars Technica

In September 2015, Apple managers had a dilemma on their hands: should, or should they not, notify 128 million iPhone users of what remains the worst mass iOS compromise on record? Ultimately, all evidence shows, they chose to keep quiet.

Are we shocked?

An email entered into court this week in Epic Games’ lawsuit against Apple shows that, on the afternoon of September 21, 2015, Apple managers had uncovered 2,500 malicious apps that had been downloaded a total of 203 million times by 128 million users, 18 million of whom were in the US.

Instead of notifying everyone of the actual breach, they only list the top 25 apps in an email, leaving users of the other 2,475 apps to their fate.

And the epic games lawsuit has provided some interesting info. For example. You can download Chrome or Firefox on a iPhone, but they are really using the Safari engine, which has some issues in that it doesn't support stuff that I want. But then Apple Knows Best, or something.

10 May 2021

People Do Value Privacy

I'm a bit shocked. 96% of US users opt out of app tracking in iOS 14.5, analytics find | Ars Technica

This is perhaps the first good news on the subject of privacy I've seen in a very long time.

When Apple released iOS 14.5 late last month, it began enforcing a policy called App Tracking Transparency. iPhone, iPad, and Apple TV apps are now required to request users' permission to use techniques like IDFA (ID for Advertisers) to track those users' activity across multiple apps for data collection and ad targeting purposes.

The change met fierce resistance from companies like Facebook, whose market advantages and revenue streams are built on leveraging users' data to target the most effective ads at those users.

There was an ad campaign to convince people to opt in, and F*c*book, in the person of Zuckerberg, claimed it would "destroy small businesses around the world." Hyprbole anyone?

Personally I can't think of anything that would convince me to "opt in," and I spend a fair amount of time opting out.

01 January 2021

Apple Hates People Doing Security Research

Because Apple is so secure. Just ask the Fanbois. Apple loses copyright battle against security start-up Corellium - The Washington Post

A federal judge in Florida threw out Apple’s claims that Corellium had violated copyright law with its software, which helps security researchers find bugs and security holes on Apple’s products.

Earlier this year, after the hackers were locked down for a couple of months and bored to action, Zerodium, one of the big Zero-day, cleraing houses, stopped paying for any Apple iOS hacks. The market was saturated. They didn't feel the need to add to their collection of ways to bypass Apple security.

So anyway, the judge dismissed Apple's suit saying that Corellium's use of Apple's stuff falls under "fair use."

and in the early part of the year, a lot of those issues revolved around iMessage. All the bad guy had to do was send you a malicious message. You didn't have to open it, or click on anything, and they owned your iPhone. Yeah. Security. Though rumor has it that Version 14 of iOS is more secure. Time will tell.

19 November 2020

Apple Has Become Big Brother

Do you remember when Apple was the answer to Big Brother? Or was that always just a lie? Apple’s MacOS caught sending user data to Apple every time an app is opened

It went from emerging as basically “alt tech” of the day, cementing this image with the famed “1984” commercial that showed a dystopian future where Apple was the antidote to tech monopolies (it was IBM back then) – to, in 2020, silently tracking every move users of its operating system, MacOS, make.

Literally tracking every app that is opened on every Mac everywhere.

Other than what program was launched, Apple in this way also knows when, and can geo-locate that user at ISP and city level. “This means that Apple knows when you’re at home. When you’re at work. What apps you open there, and how often. They know when you open Premiere over at a friend’s house on their Wi-Fi, and they know when you open Tor Browser in a hotel on a trip to another city,” Paul writes.

Oh, and all that traffic going to Apple is NOT encrypted. So not just Apple, but anyone who wants to can see the data. Governments. Hackers. ISPs. Whoever.

Because they have the RIGHT and DUTY to know EVERYTHING you do ever. Or something. You have to wonder how much of that carries over to iOS. (Hat tip to Gates of Vienna.)