Users of Apple tech have a new reason to worry. A security researcher named Sabri Haddouche, who works for an instant messaging app called “Wire,” has published a proof of concept web page. It contains a fatal exploit that can crash and restart iPhones, iPads and any Mac.
Essentially then, the entire Apple ecosystem is vulnerable. Worse, the security flaw can be exploited using nothing more than CSS and HTML code. The flaw resides in Apple’s WebKit, which is its web rendering engine used by all apps and browsers running on Apple’s OS.
Haddouche tested the exploit using Chrome, Microsoft Edge, and the Safari web browser. He got the same result each time using both a MacBook Pro and an iPhone X. Apple users are advised to exercise extreme caution when visiting any web page until a patch can be issued.
The company is currently investigating the issue, and to this point has not given their legions of users a timeframe for a possible fix.
Sadly, this isn’t the first time a flaw like this has been discovered, and it’s unlikely to be the last. If there’s a silver lining, it is that Apple has historically been quick to patch flaws of this kind, and it should be noted that Linux and Windows systems are not affected.
It’s especially worrisome for small business owners, and until Apple gives us a time frame for a fix, your best bet is to steer clear of any websites but those that are business critical, and trusted sites that you know to be safe.
Although the exploit was specifically engineered to crash Apple devices, it’s easy enough to envision a nastier implementation which could critically damage the OS, rendering the device targeted by the attack completely inoperable. Stay vigilant, and stay tuned for a fix to what could be a devastating issue.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
Western Digital has a big problem, and if you use the company’s “My Cloud” network-attached storage (NAS) storage devices, you’ve got one too. The WD My Cloud service is enormously popular because it’s so convenient, allowing both business owners and individuals to store their files, perform periodic backups, and of course, access their data from anywhere in the world.
We’ve known for some time now that the next big crisis the internet will have to come to grips with is the dramatic rise of the Internet of Things (IOT).
There’s a new report out, authored by ProofPoint, and its findings for business are grim.
Perhaps the most significant change to the browser is the addition of a new password manager, which will offer to generate a random password when you sign into a website for the first time. The randomly generated password will be securely tucked away inside your Google Account and synced across both desktop and mobile versions of Chrome.
The Internet on devices continues to be a major problem when it comes to security. Unfortunately, a big part of the reason why comes down to end users. Recently, Bitdefender released a new report entitled “The IoT Threat Landscape And Top Smart Home Vulnerabilities in 2018,” and it paints a grim picture indeed.
Microsoft is making some long overdue and welcome changes to Outlook to include the Windows and the Web-based version.
Microsoft has been making two major Windows 10 releases every year, giving businesses 18 months before they need to move to the next update. This plan and schedule is part of the company’s “Windows as a service” paradigm, designed to ensure that Windows 10 gets new features, as opposed to the company’s former practice of a new Windows release every three years.
Do you use the Chrome browser extension for the MEGA file storage service? If you do, please read this article carefully. The official extension for that service has been compromised. It has been replaced with a malware version that has the capability to steal user login data for a number of popular websites, including Github, Google, Amazon, Microsoft and more.
In 2016, an unnamed US energy company left some 30,000 records (containing information about its security assets) exposed for more than two months (a total of 70 days), in violation of energy sector cyber security regulations. When the incident was initially reported, the name of the company was withheld.