Indian agency issues 'high' security warning for iPhone, MacBook, iPad

CERT-In says vulnerability can allow a hacker to remotely gain access Apple devices

Apple, Apple Logo
Photo: Bloomberg
BS Web Team New Delhi
2 min read Last Updated : Apr 03 2024 | 4:27 PM IST
India's cybersecurity agency has warned Apple products have a “remote code execution vulnerability” in devices, meaning they are vulnerable to exploitation by hackers.

The Computer Emergency Response Team (CERT-In) said hackers can "remotely gain access on a device and execute arbitrary code on the targeted system". It said that the vulnerability is in iPhone and iPad devices with iOS and iPad OS versions prior to 17.4.1. The vulnerability is also in iOS and iPad versions before the 16.7.7 update, available on iPhone 8, iPhone 8 Plus, iPhone X, iPad gen 5, iPad Pro 9.7-inch, and iPad Pro 12.9-inch gen 1.

The agency has given a "high" severity rating to the issue. It said that the remote code execution vulnerability also affects "Apple Safari versions prior to 17.4.1, which is available for macOS Monterey and macOS Ventura; MacBook users on macOS Venture versions prior to 13.6.6; and macOS Sonoma versions prior to 14.4.1".

According to a report by India Today website, CERT-In said that the issue is due to an “out-of-bounds write issue in WebRTC and CoreMedia”, which implies that the security flaw could let a hacker trick someone into visiting a specific link, which could then be used to attack the device remotely. “Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the targeted system,” the vulnerability note on CERT-In website reads.

Steps to ensure security of Apple devices:

-Keep Apple iOS and iPad OS devices updated with the latest software
-Apply security patches provided by Apple, especially those addressing vulnerabilities highlighted by CERT-In
-When connecting to a network, prioritise secure connections and avoid unsecured or public Wi-Fi network
-Enable two-factor authentication (2FA) for an added layer of security
-Back up data to protect against data loss due to security breaches or system failures
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

Topics :Apple iPhoneApple Apple MacBook AirApple MacBook ProBS Web ReportsApple iPad

First Published: Apr 03 2024 | 3:28 PM IST

Next Story