Skip to main content
  1. Home
  2. Tablets
  3. Apple
  4. Mobile
  5. News

Recently patched vulnerabilities provided hackers complete access to iPhones

Add as a preferred source on Google

A new report from a mobile security firm has highlighted a series of vulnerabilities in previous versions of iOS that, when used in the right context, could give an attacker complete control of a user’s device. The findings were published by Zimperium, and relate to two components in particular: the IOSurface and AppleAVE kernel extensions.

These components are responsible for driving a device’s display and allowing hardware acceleration for videos, respectively — though Zimperium has outlined eight ways in which they can be used to compromise an iPhone or iPad. The vulnerabilities concern the elevation of privileges, so unscrupulous parties can be granted free rein over the system. Once they’re in, a hacker can access a variety of personally identifiable information, like the device’s GPS location data, contacts, microphone, and even photos.

Recommended Videos

The IOSurface extension in particular has been previously linked to jailbreak methods, and with the release of iOS 10.3.2, Apple has patched the issues. However, users of older devices are still left unprotected. According to Zimperium’s Adam Donenfeld, who discovered the vulnerabilities, the exploits are so discreet that they can be performed without the user’s knowledge.

“Before the patch, the only way for a user to guard itself was to install a third-party mobile protection solution,” Donenfeld told Digital Trends. “Unless patched, without a third-party mobile protection solution there’s no way for a user to know whether he’s being attacked.”

Thankfully, Donenfeld noted that Apple has acted swiftly in issuing fixes. Zimperium notified the company of its findings toward the end of March, and Apple pushed out iOS 10.3.2 to devices in mid-May. The oldest iPhone currently supported with updates is the iPhone 5, meaning the wide majority of current iOS users have been covered. Zimperium will publish an expanded proof-of-concept explaining the vulnerabilities in greater detail soon, but the report is currently being delayed at Apple’s request.

Mobile devices carry unique risks. That’s the reason why firms like Zimperium exist — to address the concerns of smartphone and tablet users, who face a very different threat from their desktop counterparts. One of the dangers Donenfeld identifies is the behavior of many mobile devices in automatically connecting to available public Wi-Fi networks.

“Network-based threats are significant and far too easy to execute,” Donenfeld said. “Plus, malware in many forms has grown at an alarming rate in recent years. We’ve seen an increasing number of mobile vulnerabilities — such as Stagefright — being discovered.”

Despite manufacturers’ and researchers’ best efforts, Donenfeld doesn’t expect the rising tide of crime to turn anytime soon.

“Mobility provides a huge number of assets with much less risk of discovery and prosecution than traditional crimes, so it is only logical that mobile threats will continue to grow.”

Adam Ismail
Former Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
I gave up physical books and my reading life has never been better
Physical books are great, but e-readers are just better. There, I said it.
supernote and book in hand

If you are a book purist, you might scoff when I recommend an e-reader instead of buying physical books, and I won't blame you. The allure of the smell of pages, the weight of the book in my hands, the whole ritual, is hard to resist. 

However, if you allow me some leeway to convince you, there’s a strong argument to be made against physical books and in favor of using e-readers. So let me make the case for e-readers, because once you understand what you've been missing, it's hard to go back.

Read more
This elusive Android tablet is the world’s thinnest and makes the iPad Pro look boring
If you thought thin tablets were Apple's thing, Huawei is here to change your mind.
Huawei MatePad Pro Max

Huawei just launched the MatePad Pro Max, and it's a lot to take in. At just 4.7mm thick and weighing 499 grams, it officially takes the crown as the world's thinnest tablet. For context, the iPad Pro, which we all fawned over for being impossibly slim, is 5.1mm thick. The MatePad Pro Max beats it.

Now, there's a decent chance you'll never actually buy this tablet. Huawei devices aren't sold in every market, and the lack of Google apps is a real barrier for most users. But there's no denying that Huawei is doing things that even Apple can’t match. 

Read more
ReMarkable Paper Pure wants to be the only notebook you’ll ever need
The ReMarkable Paper Pure is here, and it might be the perfect digital notebook for most people.
reMarkable Paper Pure

ReMarkable makes some of the best e-ink tablets on the market. However, there has always been one problem for prospective buyers: its high entry price. The ReMarkable Paper Pro costs too much, and the Paper Pro Move cannot be used as an independent device. It seems the company also realized this and is releasing a new e-ink tablet to address the issue. 

The new addition to the ReMarkable family is called the ReMarkable Paper Pure, and if you have been eyeing a ReMarkable device but didn't want to pay flagship prices, this might be the one.

Read more