After security experts discovered that last week's release of iOS 16.5 and iPadOS 16.5 patched an additional vulnerability that might expose mobile users to a new type of attack, iPhone owners urgently need to update their operating systems. one that makes use of coprocessors to reach the kernel.
ColdInvite (CVE-2023-27930), a recently mitigated vulnerability, follows ColdIntro (CVE-2022-32894), another recently discovered vulnerability. Both flaws allow attackers to bypass the coprocessor's secure "isolation environment" (chips that speed up the main processor's job completion). These chips provide attackers access to the kernel of the iPhone, a crucial component of the device's operating system.
In August 2022, Apple issued an initial fix for ColdIntro through iOS 15.6.1.
However, when examining ColdIntro, the researcher found a weakness it has named ColdInvite. A potentially crucial link in an exploit chain, ColdInvite enables attackers to leave a co-process and start memory damage in the Application Processor (AP).
Apple received a complaint from Jamf Threat about ColdInvite, a vulnerability that affects iPhone 12 and subsequent devices, and it was addressed in iOS 16.5 and iPadOS 16.5. This made it possible for the researcher to announce the discovery publicly today.
Owners of iPhones and iPads may find this news alarming, but it is important to remember that Apple has already taken proactive measures to improve the security of its products with the introduction of its new Rapid Security Response upgrades. These are specialised security updates that can be easily downloaded and deployed on Macs, iPhones, and iPads with no interference to user experience.
It's important to note that Apple leaves nothing to chance by including security fixes from Rapid Security Response releases in subsequent iOS upgrades (iOS 16.5 includes two updates from the iOS 16.4.1 (a) Rapid Security Response release). Nevertheless, the user might still be the weak link, thus iPhone and iPad owners should take greater initiative.
0 Comments