Home > News list > Mobile Internet >> Mobile Internet

Please upgrade as soon as possible. Apple iPhone/iPad has been exposed with a vulnerability: it can obtain kernel read and write permissions

Mobile Internet 2023-05-23 09:55:24 Source: Network

On May 23rd, IT Home reported that Jamf Threat Lab recently posted a blog post sharing the ColdInvite vulnerability on the iPhone, which allows attackers to exploit known ColdIntro vulnerabilities in iOS systems.Security researcher 08tc3wbb discovered some "interesting and mysterious" information while analyzing the ColdIntro vulnerability (tracking number CVE-2022-32894, which Apple fixed last year), and ultimately discovered the ColdInvite vulnerability (tracking number CVE-2023-27930)

On May 23rd, IT Home reported that Jamf Threat Lab recently posted a blog post sharing the ColdInvite vulnerability on the iPhone, which allows attackers to exploit known ColdIntro vulnerabilities in iOS systems.


Security researcher 08tc3wbb discovered some "interesting and mysterious" information while analyzing the ColdIntro vulnerability (tracking number CVE-2022-32894, which Apple fixed last year), and ultimately discovered the ColdInvite vulnerability (tracking number CVE-2023-27930).

Apple released an iOS 15.6.1 update last year to fix the vulnerability ColdIntro. The ColdIntro vulnerability is the introduction of malicious code from the Display Coprocessor (DCP) into the AP kernel; The ColdInvite vulnerability discovered this time allows attackers to bypass DCP and directly enter the AP kernel.

Although attackers are unable to fully take over devices using the ColdIntro and ColdInvite vulnerabilities, they can use the coprocessor to obtain read/write permissions to the kernel, thereby invading the device and generating greater destructive power.

IT Home has attached the list of affected Apple products as follows:

  • ColdIntro:IPhone 6s and newer models, iPad Pro (all models), iPad Air2 and newer models, iPad 5th generation and newer models, iPad mini 4 and newer models, and iPod touch (7th generation) with iOS 15.6 (and older versions of iOS) installed.

  • IPhone 12 (and subsequent models), with iOS 14 to 16.4.1 installed.

The iOS/iPadOS16.5 update recently released by Apple has fixed the ColdInvite vulnerability (tracking number CVE-2023-27930). It is recommended that users upgrade as soon as possible.


Tag: as Please upgrade soon possible. Apple iPhone iPad has


Disclaimer: The content of this article is sourced from the internet. The copyright of the text, images, and other materials belongs to the original author. The platform reprints the materials for the purpose of conveying more information. The content of the article is for reference and learning only, and should not be used for commercial purposes. If it infringes on your legitimate rights and interests, please contact us promptly and we will handle it as soon as possible! We respect copyright and are committed to protecting it. Thank you for sharing.

AdminSo

http://www.adminso.com

Copyright @ 2007~2024 All Rights Reserved.

Powered By AdminSo

Open your phone and scan the QR code on it to open the mobile version


Scan WeChat QR code

Follow us for more hot news

AdminSo Technical Support