PREVIOUS ARTICLENEXT ARTICLE
NEWS
By 29 January 2021 | Categories: news

0

Apple users may want to update their iOS and iPadOS devices to version 14.4 right away, according to cybersecurity company Kaspersky.

On January 26, Apple released a security update to close three zero-day vulnerabilities: CVE-2021-1780CVE-2021-1781, and CVE-2021-1782. Because Apple believes unnamed cybercriminals are already exploiting these vulnerabilities, the company advises all iOS and iPadOS users to update their operating systems.

According to the information available, unknown actors may already be using the three vulnerabilities as an exploit chain, but with investigations ongoing, and for users’ protection, Apple plans to delay the release of more details.

In order to stay safe, Kaspersky experts recommend carrying out the update as soon as possible. According to Apple’s website, the update is available for iPhone 6 models and newer, iPad Air 2 and newer, iPad mini 4 and newer, and the seventh-generation iPod touch.

“It is a well-known fact that infecting an iPhone or iPad and rooting the device to intercept data from it is a very difficult task. However, there is one effective method of infection - the so-called Drive-By-Download attack,” comments Victor Chebyshev, security analyst at Kaspersky.

“A target only needs to visit a specially designed web page containing an exploit that uses the vulnerability in the browser to execute the attackers' code. This is dangerous because attackers can subsequently access valuable data in the browser. However, this scenario develops further whereby a payload - another exploit - can be delivered to manipulate a vulnerability in the OS kernel.”

Chebyshev explains that this could allow attackers to get deeper into the system and gain access to all data, including chats in messenger apps and social networks, geolocation, call history and corporate mail.

“The scenario is extremely dangerous and the security update for operating system 14.4 is aimed at countering it. Why is it so important to update as quickly as possible? The possibility of falling into the above traps and scenarios is very high, as attackers tend to infect popular web platforms with a large audience for this kind of attack. And the larger it is, the higher the chance that you or people close to you will be affected,” he concludes.

For more cybersecurity insights, take a look at the excerpt of our recent exclusive Cybersecurity and AI video interview with a Kaspersky, below, and then take a look at the whole of Part 1 here.

USER COMMENTS

Read
Magazine Online
TechSmart.co.za is South Africa's leading magazine for tech product reviews, tech news, videos, tech specs and gadgets.
Start reading now >
Download latest issue

Have Your Say


What new tech or developments are you most anticipating this year?
New smartphone announcements (44 votes)
Technological breakthroughs (28 votes)
Launch of new consoles, or notebooks (14 votes)
Innovative Artificial Intelligence solutions (28 votes)
Biotechnology or medical advancements (21 votes)
Better business applications (132 votes)