HomeSecurityiCloud had a security flaw that Apple never disclosed

iCloud had a security flaw that Apple never disclosed

iCloud has had a privacy issue for users since last year, and Apple kept it a secret from the public. This isn't the first time a major company has had this happen, considering other social media companies have had similar issues, but the difference is that the other companies were quick to disclose the situation.

iCloud

Last year, an unknown group of hackers exploited a flaw in Facebook and managed to secretly gain access to millions of accounts and steal their personal information. After this incident, the company notified all affected users. Similarly, in the previous months, some vulnerabilities appeared on Twitter and the affected users were immediately informed by the company. We also do not forget that Google announced the deactivation of the Google+ platform next April to protect users.

According to official sources, Apple 's iCloud experienced a security flaw that may have exposed some of users' iCloud data to other users, but the company decided to keep the problem a secret.

How was the bug?

More specifically, a week ago, security researcher Melih Sevim contacted security and hacking sites and claimed to have discovered a flaw in Apple services that allows him to view some data, especially notes from random iCloud accounts but also the servers of iCloud users just by knowing their mobile numbers. The researcher confirmed that he found the bug in October 2018 and then reported it to the Apple team and gave them a report on how he discovered the bug, proving that he could read personal iCloud data from other Apple users without their knowledge. After a month, Apple replied to the researcher that it had already detected it and fixed it, before receiving details from him.

How did the error manifest itself?

According to the researcher, the bug had to do with the way Apple handles the internal connection that stores the phone number stored in an Apple ID's billing information in iCloud on the device that the phone number is used on. After following a few steps on his iPhone and saving a new phone number to a different Apple ID in the billing information in Settings, he was able to see some iCloud data from the account associated with that number!

What response did Apple?

In addition to the researcher, many security sites have asked the company for an explanation regarding the bug published by Malih, but the only statements Apple made were that it had already fixed the bug since November. It did not mention at all the time periods during which the bug existed or the users it affected.

If we also take into account yesterday's security flaw in Group FaceTime, it seems that Apple is unable to properly communicate with its customers and inform them in a timely manner about any error that occurs in its services.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS