Why You Should Update to the Latest iOS, OS X Versions Immediately

Advertisement
By Abhinav Lal | Updated: 22 July 2016 17:50 IST
Highlights
  • Cisco's Talos Intelligence security unit found the image-based bug
  • The bug can be used for undetected remote code execution
  • Image file formats are tiff, bmp, dae, and OpenEXR

A Cisco researcher has highlighted vulnerabilities in iOS, OS X, tvOS, and watchOS. These operating systems are said to be vulnerable to malware that's been embedded in an image file. The malware, which can allegedly run undetected, allows the attacker to achieve remote code execution on the infected system.

Cisco Talos' Tyler Bohan said that users could receive the file via MMS or email, or even be exposed to it when it's placed on a malicious webpage. The remote code execution vulnerabilities were found in the way Apple operating systems access image data using APIs - specifically, Apple Core Graphics API, Scene Kit, and Image I/O.

Image formats that can be used to exploit these vulnerabilities are tiff (tagged image file format), bmp (bitmap), dae (digital asset exchange), and OpenEXR. While the tiff and bmp formats can infect OS X, iOS, watchOS, and tvOS; OpenEXR and dae can infect only OS X machines.

Advertisement

Luckily for users of the above-mentioned Apple operating systems, the Cupertino-based company has patched all the vulnerabilities in the latest versions - iOS 9.3.3, OS X El Capitan v10.11.6, tvOS 9.2.2, and watchOS 2.2.2. If you are currently running a version older than these, it is highly recommended you update to the latest version to avoid the vulnerabilities.

Bohan on the Talos Intelligence blog post described why the vulnerabilities are especially bad. "Image files are an excellent vector for attacks since they can be easily distributed over Web or email traffic without raising the suspicion of the recipient. These vulnerabilities are all the more dangerous because Apple Core Graphics API, Scene Kit and Image I/O are used widely by software on the Apple OS X platform," he said.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts
  2. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  3. Motorola Edge 70 India Launch Date Leaked; Might Arrive With Bigger Battery
  4. Best 5G Smartphones Under Rs 10,000 in India: Galaxy M06 5G, Poco M7, More
  5. Redmi 15C 5G India Launch Today: Everything You Need to Know
  6. Motorola Smartphones in India Now Support PhonePe's Indus Appstore
  7. ISS Hits Historic Milestone: Eight Spacecraft Docked Simultaneously
  1. Pariah OTT Release: Vikram Chatterjee’s Heart-Wrenching Stray Dog Thriller Set for OTT Debut
  2. Dies Irae OTT Release: When, Where to Watch Pranav Mohanlal's Malayalam Horror Thriller Online
  3. A Nearby Planet May Have Formed the Moon Following a Collision With Early Earth: Study
  4. Netflix’s Gritty Frontier Drama The Abandons to Begin Streaming Soon: All You Need to Know
  5. Superman OTT Release Date Announced: Everything You Need to Know About Clark Kent's Latest Adventure
  6. International Space Station Makes History As Eight Visiting Spacecraft Simultaneously Dock
  7. Dulquer Salmaan’s Kaantha Set for OTT Debut: When and Where to Watch 1950's Period Drama Online?
  8. Motorola Edge 70 India Launch Date Leaked; Indian Variant Said to Feature Bigger Battery, Slim Design
  9. SpaceX Adds 29 New Starlink Satellites in Successful Falcon 9 Launch
  10. UK to Recognise Crypto as Property After Lawmakers Approve Landmark Bill
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.