iTnews

Apple iOS 9 packs huge set of security patches

By Juha Saarinen, iTnews on Sep 18, 2015 6:33AM
Apple iOS 9 packs huge set of security patches

Upgrade squishes 98 vulnerabilities.

Apple's latest version of its iOS mobile operating system comes with many new features, but also a large amount of security patches to plug vulnerabilities with varying degrees of severity.

No fewer than 98 common vulnerability and exposures database listed bugs (CVEs) have been patched in iOS 9, found by both Apple and security researchers.

In comparison, the previous iOS 8.4 took care of 34 CVEs.

iOS 9 sorts out a flaw in the AirDrop wireless file sharing feature that could be abused to plant malware on user devices in range of attacks - even when the files in question were rejected by users.

The AirDrop flaw was discovered by Australian security researcher Mark Dowd of Azimuth Security.

Information in apps is better protected in iOS 9, preventing other developers from scanning programs installed on iPhones and iPads to glean information on users and apps.

The JavaScriptCore in the WebKit page rendering platform contained memory corruption issues that meant malicious websites could arbitrarily execute code on users' devices; six CVEs covering JavaScriptCore were addressed by Apple.

In total, some 30 remotely exploitable vulnerabilities were fixed in JavaScriptCore and Webkit.

Apple also shored up SSL/TLS authentication and security of internet traffic, sorting out an issue that meant it was possible to listen in on encrypted communications due to a bug in digital certificate handling in iOS.

A number of spoofing issues that could be used to trick users into thinking they were visiting legitimate sites was also dealt with, and it's no longer possible in iOS 9 to exploit a flaw that allowed attackers to send a bogus email that appeared as though it came from a contact in the address book.

Additionally, the security code to lock devices has been lengthened to six digits from four in iOS 9, making it substantially harder to guess the sequence of numbers.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
apple infosec ios 9 security

Partner Content

Beat the DDoS blackmails in 2021
Partner Content Beat the DDoS blackmails in 2021
Why companies fail at picking cloud modernisation partners
Partner Content Why companies fail at picking cloud modernisation partners
Shut the door on ransomware
Partner Content Shut the door on ransomware
MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics
Partner Content MSI shows first laptops with Wi-Fi 6E, Nvidia RTX 30 graphics

Sponsored Whitepapers

Five questions to ask before you upgrade to a SIEM solution
Five questions to ask before you upgrade to a SIEM solution
Effectively addressing advanced threats
Effectively addressing advanced threats
The risky business of open source
The risky business of open source
Ensure your e-signatures are legally binding
Ensure your e-signatures are legally binding
Mitigating open source risk in your organisation
Mitigating open source risk in your organisation

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • Beat the DDoS blackmailers in 2021
By Juha Saarinen, iTnews
Sep 18 2015
6:33AM
0 Comments

Related Articles

  • Apple loses court case against security vendor Corellium
  • Apple could block apps that don't comply with new privacy feature
  • Apple, GroupM, others ask for tough protection for data in Google lawsuit
  • Apple hits back at European activist complaints against tracking tool
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Telstra blasts plan to 'set aside' mobile spectrum for Optus and TPG, but not it

Telstra blasts plan to 'set aside' mobile spectrum for Optus and TPG, but not it

Australia Post is building a digital twin of its delivery network

Australia Post is building a digital twin of its delivery network

Google threatens to withdraw search engine in Australia

Google threatens to withdraw search engine in Australia

Trump pardons former Google self-driving car engineer

Trump pardons former Google self-driving car engineer

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.