Why You Should Update to the Latest iOS, OS X Versions Immediately

Advertisement
By Abhinav Lal | Updated: 22 July 2016 17:50 IST
Highlights
  • Cisco's Talos Intelligence security unit found the image-based bug
  • The bug can be used for undetected remote code execution
  • Image file formats are tiff, bmp, dae, and OpenEXR

A Cisco researcher has highlighted vulnerabilities in iOS, OS X, tvOS, and watchOS. These operating systems are said to be vulnerable to malware that's been embedded in an image file. The malware, which can allegedly run undetected, allows the attacker to achieve remote code execution on the infected system.

Cisco Talos' Tyler Bohan said that users could receive the file via MMS or email, or even be exposed to it when it's placed on a malicious webpage. The remote code execution vulnerabilities were found in the way Apple operating systems access image data using APIs - specifically, Apple Core Graphics API, Scene Kit, and Image I/O.

Advertisement

Image formats that can be used to exploit these vulnerabilities are tiff (tagged image file format), bmp (bitmap), dae (digital asset exchange), and OpenEXR. While the tiff and bmp formats can infect OS X, iOS, watchOS, and tvOS; OpenEXR and dae can infect only OS X machines.

Luckily for users of the above-mentioned Apple operating systems, the Cupertino-based company has patched all the vulnerabilities in the latest versions - iOS 9.3.3, OS X El Capitan v10.11.6, tvOS 9.2.2, and watchOS 2.2.2. If you are currently running a version older than these, it is highly recommended you update to the latest version to avoid the vulnerabilities.

Bohan on the Talos Intelligence blog post described why the vulnerabilities are especially bad. "Image files are an excellent vector for attacks since they can be easily distributed over Web or email traffic without raising the suspicion of the recipient. These vulnerabilities are all the more dangerous because Apple Core Graphics API, Scene Kit and Image I/O are used widely by software on the Apple OS X platform," he said.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Buds Ace 3 Launched With Up to 54 Hours of Total Battery Life
  2. Motorola Razr+ 2026 Leaked Renders Show Design Changes
  3. This Realme 16 Series Phone Could Launch in India Soon
  4. Top Budget Smartwatches with AMOLED Display Under Rs 3,000
  5. Apple Could Bring These AI Editing Tools to Your iPhone, iPad and Mac
  1. Take-Two CEO Addresses GTA 6 Price, Says Company Focussed on Ensuring 'Reasonable' Prices for Its Games
  2. Apple Announces Monthly Payment Option for Annual Subscriptions on App Store
  3. Biker OTT Release Date Revealed: Know Everything About Plot, Cast, and More
  4. OpenAI Falls Short of Revenue and User Targets as It Races Toward IPO, WSJ Reports
  5. YouTube Tests 'Ask YouTube' AI Chatbot That Offers Smart Responses With Videos, Shorts
  6. Realme 16x 5G India Launch Seems Imminent as Storage Options, Colourways Surface Online
  7. Motorola Razr+ 2026 Leaked Renders Show Bigger Cover Screen, Design Changes
  8. Apple Reportedly Developing New AI-Powered Photo Editing Tools for iPhone, iPad, and Mac
  9. James Webb Space Telescope Reveals Cosmic Buckyballs in Distant Nebula
  10. OnePlus Buds Ace 3 Launched With Up to 55dB ANC, Up to 54 Hours of Total Battery Life: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.