Tuesday, 25 February 2014
On
06:53
by
Unknown
No comments
Every tap, touch, and press you make on your iPhone and iPad could be monitored and captured remotely due to an iOS security flaw. At least, that's the claim from security firm FireEye.
In a blog posted Monday, FireEye researchers said they conducted a test on non-jailbroken iOS 7.0.x devices in which they installed a "monitoring" app. This app was able to record all touch and press events in the background, including screen touches, home button presses, volume button presses, and TouchID presses. Based on its findings, the team concluded that an attacker could use such an app to remotely obtain keystrokes and screen touches on an iOS device, thereby reconstructing "every character the victim inputs."
The flaw reportedly lies in the way background apps run on an iPhone or iPad as those apps can detect all keystrokes and touch inputs made on the device. Disabling the Background App Refresh setting can prevent the background monitoring, though a malicious app disguised as a music program could still conduct such monitoring.
And though the researchers used a device running iOS 7.0.4, they said the same vulnerability exists in iOS versions 7.0.5, 7.0.6 and 6.1.x.
Of course, an iOS user would have to somehow allow the malicious app to be installed in the first place. Apple does impose strict requirements on the apps allowed in the App Store. FireEye was able to install its test app on a non-jailbroken device, though it didn't explain how.
Until Apple patches the problem, the only way to avoid the flaw is to trigger the iOS task manager to manually shut down apps running in the background, according to FireEye. Double-tapping the Home button displays all background apps. Swiping a background app in iOS 7.0.x then closes the app.
What is Apple's take on this reported security bug? The FireEye researchers said they've been collaborating with the company on this issue. CNET contacted Apple for comment and will update the story if the company responds.
Apple is already grappling with a security flaw that affects OS X as well as iOS. The flaw could allow an attacker to capture and modify data supposedly protected by SSL, or Secure Sockets Layer. The launch of iOS 7.0.6 late last week patched the hole for mobile devices. OS X remains exposed, though Apple has promised a fix there as well.
Subscribe to:
Post Comments
(
Atom
)
Search
Popular Posts
-
Google Barge, which has been sitting unfinished and idle alongside a pier in the middle of San Francisco Bay, will soon be on the move. ...
-
Get Battlefield 3 (PC) for free Origin's latest giveaway takes you to the front lines for awesome first-person combat. Plus: three bon...
-
Mr Banerjee's original Braille printer was made out of Lego robotics parts A 13-year-old boy from California has s...
-
Google wants to assure advertisers -- who help float its revenue boat -- that their ads are actually reaching their target audiences. To ...
-
The firm said the move was aimed at offering a more localised service to its users in China. It is expected to boost LinkedIn...
-
The incubator's inventor says it can match the performance of systems 100 times the price A prototype inflatable ...
-
Children up to the age of 13 should have only moderate exposure to 3D, the report finds A French health watchdog has recommend...
-
Pirate Bay co-founder Gottfrid Warg has been sentenced to three-and-a-half years in prison for hacking into computers and illegal...
-
Here's the sitch: You want an iPhone, but don't want to get locked into a two-year contract to the tune of $70+ per month. Without ...
-
Sony's President of Worldwide Studios, Shuhei Yoshida, just recently posted on the Driveclub Facebook page , and things aren't look...
Recent Posts
Sample Text
Blog Archive
-
▼
2014
(
367
)
-
▼
February
(
214
)
- Apple's culture of secrecy delays security respons...
- Black market lights up with 360M stolen credential...
- Why bother to text your girl when BroApp can do it...
- MTN, Globacom, Airtel fined $4m by NCC
- Bitflux wins Nigerian spectrum licence bid
- Jumia Nigeria giving away one PS4 hourly at 50% di...
- LinkedIn testing Chinese language site
- Top Bitcoin exchange MtGox goes offline
- Samsung adds biometrics to latest Galaxy smartphone
- 'Smart' toothbrush grades your brushing habits
- Bitcoin ATMs coming to the U.S.
- Feeling glum, happy, aroused? New technology can d...
- AT&T follows Verizon, offers free global texts wit...
- Apple promises to fix OS X encryption flaw 'very s...
- Quixey's mobile search lets you dig deep into apps...
- BlackBerry CEO confirms Foxconn-made Q20 and Z3 ph...
- Freescale Semiconductor's Kinetis KL03 processor...
- T-Mobile's losses widen as the carrier promotes 'U...
- Microsoft's hardware chief changes roles
- Curved Samsung Gear Fit Review
- New Movies Anywhere app streams Disney's world
- Microsoft in talks to take stake in Dailymotion, r...
- iOS security hole reportedly exposes your screen i...
- Mozilla plans '$25 smartphone' for emerging markets
- Huawei launches 'hybrid' Talkband smart device
- Xbox One price cut to match PlayStation 4
- WhatsApp will expand to voice communications in th...
- Mt. Gox resigns from Bitcoin Foundation Board
- Intel launches new Atom processors
- Broadcom aims to double Wi-Fi speeds with new 802....
- Get Password Depot password manager (Win) for free
- HTC's Desire 610 comes glad in glossy plastic, has...
- First Ubuntu phones
- SanDisk microSD cards hit 128GB
- Android-powered Nokia X great for Microsoft
- BBM to land on Windows Phone this summer
- Trace Mobile numbers or Ip-Address
- Multi Google Talk Login without any software
- 1). Start any application, say Word. Ope...
- Top 20 Tips To Keep Your System Faster
- Brief overview of Unix and Linux commands
- Increase the speed of your internet connection wit...
- HOW TO CHECK ALL PASSWORD IN FIREFOX
- ALL DOS CODES REVEALED – EVERY CODE FOR COMMAND PR...
- SOME COOL KEYBOARD SHORTCUTS FOR PC BEGINNERS
- HOW TO ENJOY WINDOWS 8 VIEW IN WINDOWS 7
- Top 10 Windows 8 tips and tricks
- Schiit Audio's tiny, but powerful $119 tube headph...
- Samsung Galaxy Tab Pro 8.4 review:
- Lie detector on the way to test social media rumours
- Security failings in Linksys and Asus home routers...
- Wurm offer Bounty for game taken offline by DDoS a...
- Stuxnet worm 'targeted high-value Iranian assets'
- South Korea to develop Stuxnet-like cyberweapons
- Netflix speeds lag for Verizon users amid dispute
- Steve Jobs may appear on U.S. postage stamp
- New app helps you fight parking tickets
- Apple security update fixes iOS vulnerability
- Fitbit halts sale of Force fitness band, issues re...
- Samsung Galaxy Gear 2 and Gear 2 Neo spied in leak...
- Google Barge to set sail for new home within a month
- BigRep 3D printer can print whole pieces of furniture
- Google's Project Tango whips up new mapping tech
- Namecheap targeted in monumental DDoS attack
- Samsung Galaxy S5: Most likely features and specs
- 5TB hard drive is here, inside LaCie's latest Thun...
- Google's Tim Bray steps down in the name of workin...
- Leaked specs paint fuller picture for HTC Desire 8
- Muvee Action Studio lets you edit your GoPro video...
- Google acquires Spider.io to combat ad fraud
- Nvidia delivers more KitKat and an LTE-equipped Te...
- Microsoft taps gamers to test next Xbox One update
- Firefox OS taps into Cordova for easier Web-app de...
- Opera: watch an ad, get free mobile Net access
- Obama's commerce secretary to petition Silicon Val...
- Airbnb makes smoke and carbon monoxide detectors m...
- Fatwa forbids Muslims from traveling to Mars
- New Fiskers will have V-8s or batteries, Wanxiang ...
- Google embarks on smart contact lenses for diabetics
- Paul Graham steps down as Y-Combinator president
- Verizon closes Vodafone deal for total control of ...
- Sprint adds Wi-Fi calling to improve voice coverage
- Amazon reportedly prepping Web TV product for March
- Nokia's Here Maps to expand to all Windows 8.1 dev...
- LinkedIn now allows you to block other members
- Supernova secrets seen in X-rays
- 3-D printing 'ink' is way too expensive
- Speculators look to cash in on Bitcoin crisis
- Blackberry boss 'outrage' at T-Mobile iPhone offer
- Malware makers 'tailor' Android threats geographic...
- Microsoft to sell $25 Xbox One Media Remote in March
- Libon to IM friends for free, even if they don't h...
- Yandex suite of free Android tools sidesteps Google
- Microsoft relaunches Office Web Apps as Office Online
- Apple eyes smart magnets to attach accessories to ...
- Another HTC One 2 leak shows new colors for handse...
- The not-so-secret appeal of Snapchat's fleeting st...
- Radiation-free cancer scans may be on the horizon
- Kazam Thunder 2 brings lightning-fast 4G LTE
- Compact, budget Liquid Z4 phone hopes to make a bi...
- Acer's Liquid E3 designed to make selfies easier
- Volvo's concept Roam Delivery service brings your ...
- Apple 'snapped up' sapphire displays, says Canonic...
- First HTC smartwatch said to get private preview n...
- An e-cigarette packed with Bluetooth? Talk to the ...
- eBay acquires PhiSix, which lets users try on 3D c...
- Data breach at University of Maryland exposes 300K...
- Signs point to first Microsoft Surface tablet with...
- LG officially unveils G2 Mini
- Netgear ships two new DOCSIS 3.0 cable modem-Wi-Fi...
- Can a simple app really give you superhero sight?
- WhatsApp: Don't sweat, Facebook buy won't change us
- 'Twitch Plays Pokemon' is now a fight for the soul...
- The best Game Boy Advance emulator for iOS is avai...
- Facebook to acquire WhatsApp for $16B.
- Utah district court is first to temporarily shut d...
- Google I/O moves to June.
- Google opens Maps' new look for all
- CodeCombat: Learn to code through dungeon crawling
- Select a startup disk in OS X
- Tiny 'flashlight' sees inside heart and blood vessels
- Apple to update iPad Air this year, no 12.9-inch i...
- iOS 7.1 said to be launching ‘around March 15′ wit...
- iOS 7 Download Links & How To Install It Yourself
- The Best Cydia Jailbreak Apps and Tweaks for iOS 7
- Which Browser Is Better for Privacy?
- Access the Secret Netflix Debug Menu on the Xbox 3...
- Manually Adjust Netflix Streaming Options With Hid...
-
▼
February
(
214
)
Copyright © 2014 Harry Jacks All Rights Reserved. Powered by Blogger.
About Me
Copyright Text
Copyright © 2014 Harry Jacks
All Rights Reserved
All Rights Reserved


0 comments :
Post a Comment