Why You Should Update to the Latest iOS, OS X Versions Immediately

Advertisement
By Abhinav Lal | Updated: 22 July 2016 17:50 IST
Highlights
  • Cisco's Talos Intelligence security unit found the image-based bug
  • The bug can be used for undetected remote code execution
  • Image file formats are tiff, bmp, dae, and OpenEXR
Why You Should Update to the Latest iOS, OS X Versions Immediately

A Cisco researcher has highlighted vulnerabilities in iOS, OS X, tvOS, and watchOS. These operating systems are said to be vulnerable to malware that's been embedded in an image file. The malware, which can allegedly run undetected, allows the attacker to achieve remote code execution on the infected system.

Cisco Talos' Tyler Bohan said that users could receive the file via MMS or email, or even be exposed to it when it's placed on a malicious webpage. The remote code execution vulnerabilities were found in the way Apple operating systems access image data using APIs - specifically, Apple Core Graphics API, Scene Kit, and Image I/O.

Image formats that can be used to exploit these vulnerabilities are tiff (tagged image file format), bmp (bitmap), dae (digital asset exchange), and OpenEXR. While the tiff and bmp formats can infect OS X, iOS, watchOS, and tvOS; OpenEXR and dae can infect only OS X machines.

Luckily for users of the above-mentioned Apple operating systems, the Cupertino-based company has patched all the vulnerabilities in the latest versions - iOS 9.3.3, OS X El Capitan v10.11.6, tvOS 9.2.2, and watchOS 2.2.2. If you are currently running a version older than these, it is highly recommended you update to the latest version to avoid the vulnerabilities.

Bohan on the Talos Intelligence blog post described why the vulnerabilities are especially bad. "Image files are an excellent vector for attacks since they can be easily distributed over Web or email traffic without raising the suspicion of the recipient. These vulnerabilities are all the more dangerous because Apple Core Graphics API, Scene Kit and Image I/O are used widely by software on the Apple OS X platform," he said.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo Y400 Pro 5G Confirmed to Launch in India Soon, Design Teased
  2. Vivo X Fold 5 Battery Capacity Revealed in Latest Teaser
  3. Lava Storm Play 5G, Storm Lite 5G Launched in India: Price, Availability
  4. Oppo K13x 5G Build, Durability Details Revealed Ahead of India Launch
  5. OnePlus Bullets Wireless Z3 to Launch in India on June 19: All Details
  6. The Company Behind Arc Is Now Bringing an AI Browser With Chatbot
  1. Vivo X200 FE Specifications Leaked, May Feature MediaTek Dimensity 9300+ Chipset
  2. Vivo Y400 Pro 5G Will Soon Make Its Way to the Indian Market, Rear Design Teased
  3. Samsung Galaxy Tab S11 Spotted on Geekbench; Suggests SoC Details, Benchmark Scores
  4. The Browser Company Unveils Dia, an AI-Powered Browser With In-Built Chatbot
  5. OnePlus Bullets Wireless Z3 India Launch Date Set for June 19; Colour Options, Battery Details Revealed
  6. Blaupunkt Launches 2025 Lineup of QLED Google TVs in India: Price, Specifications
  7. Razer Kishi V3, Kishi V3 Pro and Kishi V3 Pro XL Mobile Gaming Controllers With Sensa HD Haptics Launched
  8. Microsoft Expands Copilot Vision With Highlights on Windows, Can Work With Two Apps Simultaneously
  9. Vivo T4 Lite 5G Price in India, Launch Timeline Leaked; Said to Pack 6,000mAh Battery
  10. Vivo X Fold 5 Confirmed to Pack 6,000mAh Battery; to Get Periscope Telephoto Camera
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.