Mobile menu toggle

Apple security flaws

Read Cult of Mac’s latest posts on Apple security flaws:

Apple faces Hide My Email lawsuit over privacy flaw it allegedly failed to fix

By

A picture of Apple's Hide My Email feature used in a story about the same.
The Hide My Email lawsuit claims Apple knew its address-hiding feature was broken and kept selling anyway.
Photo: Apple

Apple is facing a new Hide My Email lawsuit, and it does not look good. A proposed class-action suit claims the company sold customers privacy promises it couldn’t deliver on.

The suit says Apple knew about a certain flaw in its address-hiding feature for more than a year, but kept marketing Hide My Email as airtight privacy the whole time.

Apple’s Hide My Email has been leaking real addresses for a year

By

A photo of Apple's Hide My Email feature used in a story about a security exploit affecting the service for almost more than a year.
Hide My Email is supposed to keep your real address off signup forms — but a year-old bug means it may not be doing that.
Photo: Apple

Apple’s Hide My Email has one job — to keep your real inbox out of other people’s hands. But it isn’t doing that job, and Apple reportedly knew this for more than a year.

If you’ve ever used Hide My Email to sign up for a sketchy app or website, you’ll want to pay attention. A security researcher says he managed to unmask the real email address behind virtually every Hide My Email alias. And Apple hasn’t fixed it yet.

AirDrop vulnerability lets anyone nearby knock it offline, no tap required

By

An image of Apple's AirDrop feature used in a story about recently discovered exploits.
AirDrop's convenience comes from processes that respond before you even see a prompt, which is exactly the problem.
Photo: Apple

A newly discovered AirDrop vulnerability means someone sitting in the same café as you can silently break AirDrop on your iPhone or Mac, no tap or pairing required. They just send a stream of junk data to your iPhone and AirDrop — alongside AirPlay, Handoff, Universal Clipboard, and Continuity Camera — all go dark for as long as they keep it up.

That’s the core finding from new security research into Apple’s AirDrop protocol. The exploit does not steal any data, but instead lets an attacker shut down AirDrop and Continuity features. For Apple users who use AirDrop regularly, that could be a real annoyance hiding in a real-life vulnerability.

macOS security flaw lets hackers disable Mac protection tools without a password

By

A photo showing macOS used in a story about a newly discovered macOS security flaw.
The flaw exploits how macOS apps establish trust with background services.
Photo: XM Cyber

Security researchers have disclosed a new macOS flaw that lets attackers shut down your security software after getting onto your machine — no admin password, no kernel exploit, and almost no trace left behind.

The attack takes advantage of how macOS apps earn each other’s trust, and if you use a Mac at work, it is exactly the type of thing your IT needs to know about.

Your old iPhone has a security flaw, and there’s nothing Apple can do to fix it

By

A photo of the usbliter8 iPhone security flaw used in a story about the same.
The iPhone XR, XS and 11 are among the older models affected by the newly disclosed usbliter8 exploit.
Photo: Paradigm Shift

Still holding onto an iPhone XS, XR or 11 because it gets the job done? There’s now a good reason to upgrade: usbliter8. This security flaw lets anyone with physical access to an older iPhone hijack the startup process, and Apple won’t be able to patch it with a software update.

That’s because it isn’t an iOS bug — the flaw is in the chip’s boot code, the first thing that runs when you turn on the device.

Install these iPhone, Mac and iPad security patches right now

By

iOS 18.6.2 needs to be installed now
iOS 18.6.2 needs to be installed now. The same goes for macOS 15.6.2 and iPadOS 18.6.2.
Image: Apple/Cult of Mac

Apple released iOS 18.6.2, macOS Sequoia 15.6.2 and iPadOS 18.6.2 on Wednesday, warning that the updates close security vulnerabilities already exploited by hackers.

While the patches include no new features, they are nevertheless highly recommended for iPhone, Mac and iPad users.

iOS 12.5.5 update blocks Pegasus spyware from older iPhones

By

iOS update blocks Pegasus spyware from iPhones
Install iOS 12.5.5 on your older iPhone to protect it from the Pegasus spyware.
Photo: Андрей Сидоренко/Pixabay/Cult of Mac

iPhone models that can’t install iOS 14 or iOS 15 can still get protection from the infamous Pegasus spyware thanks to iOS 12.5.5. Apple released this update Thursday for devices as old as the iPhone 5s to close a security hole in active use by hackers.

The same update can also be installed on older iPad and iPod touch models.

How Apple’s tight rein on iPhone security helps hackers

By

Hackers are always trying to crack iPhone security
While criminals probably can‘t hack an iPhone, government agencies can.
Photo: Soumil Kumar/Pexels CC

Apple keeps a very tight lid on iPhone security, but that might actually benefit very sophisticated hackers, according to some security experts.

This is how Saudi Arabia was allegedly able to hack Jeff Bezos’s iPhone X.

How to protect your Mac, iPhone, iPad from Efail email exploit

By

EFAIL lets hackers read encrypted emails on your iPhone.
EFAIL lets hackers read encrypted emails on your iPhone.
Photo: Ed Hardy/Cult of Mac

Researchers in Europe have discovered a way to read the contents of encrypted emails sent with iOS and macOS devices. The so-called Efail exploit is significant enough that the Electronic Frontier Foundation calls it an “immediate risk.”

Apple is certainly working on a patches for all its devices, but there are ways to protect your laptop, phone and tablet now.

Apple shrugs off recent bugs as ‘one bad week’

By

Phil Schiller said Apple won't release the HomePod till it's satisfied with the quality.
Phil Schiller said Apple won't release the HomePod till it's satisfied with the quality.
Photo: Digital Trends

Apple fans and enthusiastic gadget reviewers will ultimately remember 2017 as the year of a reinvented iPhone. But as the year draws to an end, Apple marketing chief Phil Schiller has a few other things on his mind, such as delays in releasing the company’s first smart speaker and a “bad week” of software bugs and security holes.

In-app purchases flaw exposes developers to costly hacks

By

App Store icon
Business is booming for the App Store.
Photo: PhotoAtelier/Flickr

Sloppy coding in some popular iOS games allows hackers to give themselves and others thousands of dollars’ worth of in-app purchases for free.

The hole was discovered by developers at DigiDNA, creator of a backup tool called iMazing that allows iPhone and iPad users to access their devices’ hidden file systems. The developers found that the app backup/restore feature in iMazing 1.3 exposes weaknesses in the way games like Angry Birds 2 and Tetris Free handle in-app purchases.

To demonstrate how easy it is to hack in-app purchases using this method, the DigiDNA team tweaked Angry Birds 2 to start the game with 999,999,999 gems — the equivalent of $10,000 of in-game credits.