[ad_1]
Critical security flaw discovered in iOS and iPadOS
A serious security flaw in Apple’s iOS and iPadOS operating systems has caused a stir in the tech world. The vulnerability allows the VoiceOver feature, which is actually intended for accessibility, to read saved passwords out loud. This issue affected a variety of iPhone and iPad models and poses a significant security risk.
Having passwords read aloud by an assistive technology such as VoiceOver is particularly critical. It compromises the confidentiality of sensitive data and could potentially allow unauthorized access to personal accounts.
The vulnerability, identified as CVE-2024-44204, was described as a logic issue in the new password app.
Apple’s reaction
It affected devices from iPhone XS upwards as well as various iPad models, including the iPad Pro, iPad Air from the third generation and the iPad mini from the fifth generation. Apple responded promptly to the discovery and released a security update. In one official announcement the company explained:
A user’s saved passwords could be read aloud by VoiceOver. This issue was resolved through improved validation.
Apple emphasized that the problem was quickly resolved. Users are strongly encouraged to turn on their devices iOS 18.0.1 or update iPadOS 18.0.1 to protect yourself from possible risks.
Background and other security gaps
The vulnerability emerged shortly after the launch of iOS 18 and iPadOS 18, which included Apple’s first native password manager, the “Passwords” app. It remains unclear whether the problem was directly related to this new app or lay in another area of the operating system.
In addition to the VoiceOver vulnerability, the update also addressed another security vulnerability that specifically affected the new iPhone 16 models:
- CVE-2024-44207: Allowed a few seconds of audio to be recorded during voice messages in the Messages app before activating the microphone indicator.
- Solution: This problem has also been resolved with improved checking mechanisms.
The discovery of these vulnerabilities underscores the importance of regular software updates and shows that even large technology companies like Apple are not immune to errors. Notably, the VoiceOver vulnerability was discovered and reported by a third-party security researcher, Bistrit Daha, highlighting the importance of independent security audits.
What do you think about this security vulnerability? Do you use VoiceOver or other accessibility features and have you possibly been affected by the issue? Share your experiences and thoughts in the comments!
See also:
[ad_2]
Source link