HomeSecurityApple challenges ZecOps over iOS vulnerability exploitation

Apple questions ZecOps over exploiting iOS vulnerabilities

Apple

Apple issued a statement saying it “thoroughly investigated” ZecOps ’ recent report about hackers exploiting three iOS zero-day vulnerabilities , but “found no evidence that the vulnerabilities were used against customers. ”

The day before yesterday, a report by security ZecOps, detailing three iOS vulnerabilities affecting the Apple Mail client.

ZecOps stated that the vulnerabilities had been used by hackers to carry out attacks on VIP targets:

  • Employees of Fortune 500 companies in North America
  • A transportation company executive in Japan
  • A VIP from Germany
  • MSSP from Saudi Arabia and Israel
  • A journalist in Europe
  • And most likely, a director of a Swiss company

However, in a statement published by Apple, it says it reviewed the details shared by ZecOps in its report and did not reach the same conclusion, namely that the vulnerabilities have been exploited by hackers.

Apple's full statement is below:

“Apple takes all reports of security threats seriously. We have thoroughly investigated the researchers’ report and, based on the information provided, we have concluded that these issues do not pose an immediate risk to users . our The researchers identified three issues in Mail, but these alone are not sufficient to bypass the security protections of iPhone and iPad , and we have found no evidence that they were used against our customers. These potential issues will be addressed in a software update soon . We value our partnership with security researchers to keep our users safe, and we thank the researchers for their assistance.”

ZecOps' research sparked backlash not only from Apple but also on Twitter, with several iOS security researchers questioning the conclusion that the bugs had been used in attacks.

ZecOps researchers believed the vulnerabilities were being exploited by hackers due to crash logs found on the device.

These crash logs were interpreted as attempts to exploit vulnerabilities.

ZecOps said the failed exploit left a blank email and a crash log on the device. According to the company, a successful exploit leads to the deletion of the blank emails to hide the attacks.

iOS

Security researchers pointed out that if the attacker can delete the emails, they can probably delete the crash logs as well.

The opposing view says that the researchers simply saw problematic emails that trigger a (non-malicious) bug, and not malicious attacks against iOS users. Apple needs more evidence to classify these crash bugs as attacks.

ZecOps

Responding to a Reuters report today, ZecOps promised to release more information about the bugs once Apple releases a patch.

The bugs have been fixed in the iOS 13.4.5 beta and the fix is ​​expected to reach the iOS stable channel in the coming weeks.

The full statement from ZecOps is as follows:

“According to ZecOps data, there were attacks due to these vulnerabilities in some organizations. We want to thank Apple for working on a patch and look forward to updating our devices once it is available. ZecOps will release more information and POCs when the update is available.”

The existence of the bugs has never been disputed by Apple or the security community, and it is recommended that you install iOS 13.4.5when it is released.

In its statement, Apple wanted to make it clear that it was taking the researchers' reports into account, but said that the conclusion of this particular report could not be verified, at least for now.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS