HomeSecurityApple fixes serious encryption flaws in iMessage

Apple fixes serious encryption flaws in iMessage

Updates for iOS and Mac OS X released by Apple on Monday address serious encryption flaws that affect the company's iMessage protocol, which is used to send more than 200,000 messages every second.

 Apple
A research team from Johns Hopkins University, led by cryptography expert Matthew Green, has discovered new attack methods that, under very specific conditions, can be used to decrypt iMessage attachments, such as videos and photos
According to a study published on Monday, and after Apple released patches to address the vulnerability, experts explained that if an attacker manages to obtain iMessage ciphertexts, they can silently decrypt the attached messages, as long as the sender or recipient's device is online.
The attack is made more difficult if certificate pinning, a security mechanism designed to prevent the use of fake certificates, has been implemented, but an experienced and powerful attacker, such as a state-sponsored agent, or a hacker with access to Apple's servers, can carry out the attack.
In the advisory issued by the company regarding the vulnerability, which has been given the identifier CVE-2016-1788, Apple notes that an attacker would need to bypass certificate pinning, breach TLS connections, inject messages, and capture encrypted attachments to successfully carry out the attack.
In addition to the iMessage vulnerability, Apple fixed dozens of other security issues across many of its software products, including iOS, OS X, watchOS, tvOS, Xcode, OS X Server, and Safari.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS