iTnews

Apple update fixes major flaws in iPhones, iPads

By Dan Kaplan on May 8, 2012 9:09AM
Apple update fixes major flaws in iPhones, iPads

Hole remains in Apple desktop browser.

Apple on Monday pushed out a security update for its iOS mobile operating system to patch four vulnerabilities. 

Affected components are Safari and WebKit, the open-source engine used to render web pages. The most serious of the bugs is a "memory corruption" defect that can lead to the remote execution of malicious code. 

Two of the WebKit flaws could result in cross-site scripting attacks, and both were discovered by researcher Sergey Glazunov.

One of those was uncovered at the MarchPwnium hacker competition at the CanSecWest security conference in whichhackers aimed to defeat the Chrome browser's sandbox architecture. 

WebKit also powers Chrome, and Glazunov was awarded $60,000 for his discovery.

Google almost immediately patched the flaw, but despite plugging the hole in iOS, Apple has yet to fix the issue on its desktop browser. 

The iOS update to version 5.1.1 covers iPhones and iPads.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
applecansecwestiosipadiphonepatchingpwniumsecurityvulnerabilitieswebkit

Partner Content

The case for postponing mainframe migration has eroded
Partner Content The case for postponing mainframe migration has eroded
Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
Vast majority of surveyed firms still rely on password authentication
Promoted Content Vast majority of surveyed firms still rely on password authentication
Teaching tech teams every step of implementing a machine learning project
Promoted Content Teaching tech teams every step of implementing a machine learning project

Sponsored Whitepapers

Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don’t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • 11th Annual Fraud Prevention Summit 2022
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Dan Kaplan
May 8 2012
9:09AM
0 Comments

Related Articles

  • Unc0ver jailbreak opens up Apple iOS 11 to 13.5
  • Apple patches actively exploited macOS Big Sur bug
  • Apple's "Find My" feature created attack vector, researchers say
  • Flaw in iPhone, iPads may have allowed hackers to steal data for years
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Kmart Australia stands up consent-as-a-service platform

Kmart Australia stands up consent-as-a-service platform

Telstra to open its 5G network to wholesale customers

Telstra to open its 5G network to wholesale customers

Macquarie Bank creates a broker portal on Salesforce

Macquarie Bank creates a broker portal on Salesforce

Active Directory defaults lead to no-fix PrivEsc vulnerability

Active Directory defaults lead to no-fix PrivEsc vulnerability

Digital Nation

Metaverse hype will transition into new business models by mid decade: Gartner
Metaverse hype will transition into new business models by mid decade: Gartner
The other ‘CTO’: The emerging role of the chief transformation officer
The other ‘CTO’: The emerging role of the chief transformation officer
As NFTs gain traction, businesses start taking early bets
As NFTs gain traction, businesses start taking early bets
Case Study: PlayHQ leverages graph technologies for sports administration
Case Study: PlayHQ leverages graph technologies for sports administration
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
COVER STORY: From cost control to customer fanatics, AI is transforming the contact centre
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.