CERT-In issues 'very high' level warning for iPhone and iPad users: Details
Cert-In stated that when the vulnerabilities in iOS and iPadOS would be exploited, the devices might become unresponsive or non-functional
Aashish Kumar Shrivastava New Delhi The Indian Computer Emergency Response Team (CERT-In) has issued a “high-severity” warning for Apple iOS and iPadOS users. A vulnerability in iPhone XS and later running on
iOS 18.3 has been detected leaving the devices unresponsive and non-functional. CERT-In issued “Very High” risk warning on May 12.
Who is affected
iOS versions prior to 18.3 (for iPhone XS and later)
iPadOS versions prior to 17.7.3 (for iPad Pro 12.9-inch 2nd generation, iPad Pro 10.5-inch, and iPad 6th generation)
iPadOS versions prior to 18.3 (for iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later)
What is the risk
CERT-In wrote: “A vulnerability in Apple's iOS and iPadOS may allow certain malicious applications to be unresponsive or non-functional until restored.”
If exploited, these vulnerabilities could let malicious apps render affected devices unresponsive or unusable until they are reset.
Where does it stem from
The issue stems from the ability of any iOS app to send critical system-level Darwin notifications without requiring elevated permissions or special entitlements.
While explaining the issue, the government body wrote: “The vulnerability arises due to the fact that any iOS application can transmit sensitive system-level Darwin notifications without needing special privileges or entitlements."
Darwin notifications are a fundamental messaging mechanism within the CoreOS layer, allowing different processes to send and receive system-wide event updates.
How to keep your device protected
CERT-In has advised consumers to apply appropriate fixes that Apple has mentioned in its advisory.
Meanwhile, it is advised that consumers keep their devices updated with the latest security patches.
*Subscribe to Business Standard digital and get complimentary access to The New York TimesSubscribeRenews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Complimentary Access to The New York Times

News, Games, Cooking, Audio, Wirecutter & The Athletic
Curated Newsletters

Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
Seamless Access Across All Devices