Categories: MobileNews

An iOS security vulnerability can leak your iCloud credentials

A security researcher at Ersnt & Young highlighted a security vulnerability in the native Mail app of iOS which can leak any iCloud account credentials through a legitimate iCloud account authentication popup. This vulnerability affects all users using the latest iOS 8.3 on their iPhones and iPads.

Jan Soucek, a security specialist employed at E&Y disclosed this vulnerability to Apple in January but did not get a response till recently. The bug was not addressed in any iOS version update after 8.1.2 from January onwards till now. The details of the flaw were kept private by Jan and when Apple did not fix it he decided to make the code public to highlight the risk users were exposed to.

The vulnerability allows malicious hackers to use official look alike iCloud authentication popups. Users entering their iCloud user id and passwords which, then, hackers can easily steal.

Errata Security CEO Rob Graham, while talking to Ars Technica stated:

“Errata Security CEO and longtime iPhone user Rob Graham said he considered the vulnerability serious because it’s not uncommon for iOS to display login prompts at unexpected times. He told Ars he had received one such prompt earlier Wednesday, a few hours before reading of the weakness. He said the best thing users can do when encountering such a prompt is to press the cancel button without entering any login credentials. Most of the time users will face no ill consequences, and the worst that can happen is they will be prompted again. When users do enter their password into the box, they should make sure they do so when no e-mails are displayed.”

An Apple spokesman stated that they are not aware of any user being impacted by this vulnerability. They have recommended users to enable two-factor authentication (2FA) for their iCloud accounts to deter this particular attack. It was also mentioned that a fix will be made available to users in a future software update.

Image Credits: idownload blog, MacWorld 

 

Sponsored
Mohammad Farooq

Farooq is currently writing for Dawn and TechJuice. He is also volunteering for Digital Rights Pakistan.

Share
Published by
Mohammad Farooq

Recent Posts

Pakistanis To Get Cheap Mobile Phones? Here’s What We Know!

ISLAMABAD: The federal government, under the leadership of the Pakistan Muslim League-Nawaz (PML-N), has announced…

31 mins ago

Punjab Schools to Skip Winter Camps This Vacation

LAHORE: The application made by private school owners to host winter camps in schools across…

1 hour ago

80% Chinese-Owned Processing Zone Approved in Balochistan

In the Chagai district of Balochistan, a new Export Processing Zone (EPZ) was authorized by…

3 hours ago

Google Rolls Out its Innovative ‘Reasoning’ AI Model

Google has unveiled what it calls a new "reasoning" AI model — although it is…

4 hours ago

Facial Recognition System to Be Launched by NADRA for Senior Citizens in Pakistan

The National Database and Registration Authority (NADRA) has revealed plans to introduce a facial recognition…

4 hours ago

MDCAT Retake Scheduled for December 30 in Islamabad

The Islamabad High Court has announced its decision, prompting Shaheed Zulfiqar Ali Bhutto Medical University…

4 hours ago