iOS 7 bugs

New very serious vulnerability in Apple iOS allows access to Touch ID

Researchers from FireEye revealed a new bug in iOS που επιτρέπει σε μια κακόβουλη εφαρμογή να παρακολουθεί και να συνδεθεί χρησιμοποιώντας τα δεδομένα αφής ενός χρήστη ενώ λειτουργεί στο παρασκήνιο. Το νέο exploit φέρεται να στοχεύει ένα ελάττωμα στις δυνατότητες multitasking του iOS “για να έχει πρόσβαση στα δεδομένα των χρηστών, και πραγματοποιεί την them to a remote server.

iOS-7-bug

Για να αποδείξουν την ευπάθεια, οι ερευνητές δημιούργησαν ένα POC () των δράσεων της κακόβουλης εφαρμογής και ανέπτυξαν προσεγγίσεις για την αποτελεσματική to "bypass" Apple's App Store. Once the app is installed on an iOS device, it starts recording what happens on the keyboard, data volume usage, home and power buttons, touches on the screen as well as all activities from Touch ID. All this is recorded and stored!
The researchers also noted that the malicious application disables the iOS "Background App Refresh" setting so that you do not disable the malicious app from data logging.

fig2

FireEye reports:

Note that our demo exploits the latest 7.0.4 version of the iOS system on a non-jailbroken iPhone 5s device successfully. We have found that the same sensitivity is available in iOS 7.0.5, 7.0.6, and 6.1.x versions. Based on the findings, potential attackers can use either phishing attacks or mislead the victim and install a malicious application or exploit another remote sensitivity of some apps, and then conduct background tracking.

fig1

The team added that they are actively working with Apple to fix the problem. The news comes less than a week after Apple released the iOS 7.0.6 update to identify an SSL vulnerability that allowed hackers to obtain or modify Safari and other apps data in allegedly secure sessions.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).