Advertisement
Singapore markets closed
  • Straits Times Index

    3,290.76
    +18.04 (+0.55%)
     
  • S&P 500

    5,070.55
    +59.95 (+1.20%)
     
  • Dow

    38,503.69
    +263.71 (+0.69%)
     
  • Nasdaq

    15,696.64
    +245.33 (+1.59%)
     
  • Bitcoin USD

    66,503.73
    +203.84 (+0.31%)
     
  • CMC Crypto 200

    1,435.91
    +11.81 (+0.83%)
     
  • FTSE 100

    8,082.81
    +38.00 (+0.47%)
     
  • Gold

    2,332.40
    -9.70 (-0.41%)
     
  • Crude Oil

    83.08
    -0.28 (-0.34%)
     
  • 10-Yr Bond

    4.5980
    -0.0250 (-0.54%)
     
  • Nikkei

    38,460.08
    +907.92 (+2.42%)
     
  • Hang Seng

    17,201.27
    +372.34 (+2.21%)
     
  • FTSE Bursa Malaysia

    1,570.95
    +9.31 (+0.60%)
     
  • Jakarta Composite Index

    7,180.04
    +69.22 (+0.97%)
     
  • PSE Index

    6,572.75
    +65.95 (+1.01%)
     

Researchers found flaws in Apple’s software that hackers can use to ‘demolish, break and hijack’ iPhones

A skull mask
A skull mask

Reuters Pictures

FireEye uncovers fresh iOS Masque flaws.

A trio of vulnerabilities have been uncovered in Apple’s iOS operating system that can be used by hackers to forcibly “demolish, break and hijack” iPhones and iPads.

Researchers at security firm FireEye reported uncovering the iPhone and iPad vulnerabilities in a threat advisory. 

The first flaw, codenamed “Manifest Masque,” affects users who install third-party apps from sources other than the official Apple Store — something Apple works pretty hard to stop you doing.

The second flaw, “Extension Masque,” relates to the way iPhones and iPads protect apps from malware.

ADVERTISEMENT

The combination of flaws can reportedly be exploited by hackers when the user installs a third-party app and grants attackers a variety of powers.

Greg Day, FireEye’s CTO EMEA, told Business Insider these flaws include the ability to “kill, replace or tamper with apps” already installed on the iPhone or iPad and access personal data, such as call logs, contacts and GPS locations.

The hackers could also theoretically use them to install dangerous applications that hijack control of the victim iPhone or iPad, he added. The firm has yet to see any of these activities in the wild.

The third vulnerability, “Plugin Masque,” relates to the way iPhones and iPads deal with Virtual Private Network (VPN) traffic. VPNs are custom security services designed to make it more difficult for hackers and government agents to monitor users’ digital movements and communications.

The flaw could reportedly be exploited by attackers to hijack outgoing and incoming data, even if the VPN is turned on.

FireEye privately reported the bugs to Apple prior to publicly disclosing them and they have been fixed in Apple’s latest iOS 8.4. However, FireEye claims that a third of iPhones and iPads are still vulnerable to the attack and “have not updated to versions 8.1.3 or above.”

Apple did not respond to Business Insider’s request for comment at the time of publishing.

The two new Masque bugs are the latest in a long line of iOS vulnerabilities to be uncovered by FireEye. FireEye reported uncovering a separate wave of iOS bugs in February.

The report follows the release of a wave of security updates for the OS X operating system used on Apple’s popular MacBook range of laptops, some of which could also be used to hijack control of victim’s machines.

NOW WATCH: We tried the ‘belly button challenge’ that’s taking over China — and it’s way harder than it looks


The post Researchers found flaws in Apple’s software that hackers can use to ‘demolish, break and hijack’ iPhones appeared first on Business Insider.