Article Details

Scrape Timestamp (UTC): 2024-10-05 04:57:12.658

Source: https://thehackernews.com/2024/10/apple-releases-critical-ios-and-ipados.html

Original Article Text

Click to Toggle View

Apple Releases Critical iOS and iPadOS Updates to Fix VoiceOver Password Vulnerability. Apple has released iOS and iPadOS updates to address two security issues, one of which could have allowed a user's passwords to be read out aloud by its VoiceOver assistive technology. The vulnerability, tracked as CVE-2024-44204, has been described as a logic problem in the new Passwords app impacting a slew of iPhones and iPads. Security researcher Bistrit Daha has been credited with discovering and reporting the flaw. "A user's saved passwords may be read aloud by VoiceOver," Apple said in an advisory released this week, adding it was resolved with improved validation. The shortcoming impacts the following devices - Also patched by Apple is a security vulnerability (CVE-2024-44207) specific to the newly launched iPhone 16 models that allows audio to be captured before the microphone indicator is on. It's rooted in the Media Session component. "Audio messages in Messages may be able to capture a few seconds of audio before the microphone indicator is activated," the iPhone maker noted. The problem has been fixed with improved checks, it added, crediting Michael Jimenez and an anonymous researcher for reporting it. Users are advised to update to iOS 18.0.1 and iPadOS 18.0.1 to safeguard their devices against potential risks.

Daily Brief Summary

MALWARE // Apple Fixes VoiceOver Flaw and iPhone 16 Audio Bug

Apple has released updates for iOS and iPadOS to fix critical security issues.

One vulnerability, identified as CVE-2024-44204, enabled Apple's VoiceOver technology to read out saved passwords aloud due to a logic problem in the Passwords app.

This security flaw affected a range of iPhone and iPad devices.

Another issue (CVE-2024-44207) discovered in iPhone 16 models allowed the capture of audio before the microphone indicator was activated.

Security improvements include enhanced validation for the password flaw and improved checks for the audio recording issue.

The vulnerabilities were reported by Bistrit Daha, Michael Jimenez, and an anonymous researcher.

Apple advises users to update their devices to iOS 18.0.1 and iPadOS 18.0.1 to protect against these security risks.