联邦机构对苹果设备发出安全警告,并给予三周时间遵守
Federal Agency Issues Security Warning For Apple Devices, Gives Three Weeks To Comply

原始链接: https://www.zerohedge.com/political/federal-agency-issues-security-warning-apple-devices-gives-three-weeks-comply

美国政府机构 CISA 最近对 iPhone、iPad、MacBook 和其他 Apple 设备构成的重大安全风险表示担忧。 此错误会影响“点身份验证”,可能导致对美国联邦企业的重大攻击。 各机构必须在 2024 年 2 月 21 日之前应用此修复程序,而 CISA 强烈敦促所有组织解决此问题。 该问题涉及避免指针身份验证的能力,这可能会导致对数据的未经授权的访问。 幸运的是,Apple 早些时候宣布,在最近的 iPhone、iPad、Mac 和 TV 更新中解决了影响 iOS 和 iPad OS 的多个安全问题; 其中包括据报道试图在华盛顿特定民间社会组织成员的 iPhone 上使用 NSO Group 的 Pegasus 间谍软件。 为了确保您受益于这些新的安全措施,请转到手机的“设置”,选择“常规”,然后点击“软件更新”。 一旦可用,您的更新过程应该自动开始,但如果未启用自动更新,您可能需要手动搜索。 或者,您可以在 Apple 官方网站上查看完整的发行说明列表。

相关文章

原文

Authored by Jack Phillips via The Epoch Times (emphasis ours),

This week, a federal agency sent a warning about a vulnerability that impacts iPhones, iPads, Macbooks, and other Apple devices, saying that it could lead to major security breaches.

An Israeli woman uses her iPhone in front of the building housing the Israeli NSO group in Herzliya, near Tel Aviv, on Aug. 28, 2016. (Jack Guez/AFP via Getty Images)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), an arm of the U.S. Department of Homeland Security, said on Jan. 30 that the issue, marked as CVE-2022-48618, can bypass “pointer authentication.” It said that not fixing the bug could pose a “significant” risk to the U.S. “federal enterprise.”

The bulletin also said that it issued a “binding operational directive” to issue updates to fix the problem, requiring federal civilian agencies to “remediate identified vulnerabilities by the due date to protect” its “networks against active threats.”

According to CISA, the agencies were given about three weeks to patch the issue. The deadline was set for Feb. 21, 2024.

But CISA also warned that it “strongly urges all organizations,” such as companies, to respond to the bug.

On a separate website, officials say that the issue has been fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and, iPadOS 16.2, and tvOS 16.2. “An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1,” the bulletin said.

In a separate instance last month, CISA sent out an advisory for iPhone and other iOS users to update their products for another security issue.

Apple has released security updates for iOS and iPadOS, macOS, Safari, watchOS, and tvOS. A cyber threat actor could exploit some of these vulnerabilities to take control of an affected system,” said the agency on Jan. 23. It then recommended that users update their software.

As usual, Apple provided few details about the fixes in the latest update, which applies to iPhones and iPads. But one of the fixed issues, known as CVE-2024-23222, was a vulnerability in WebKit, which runs the Safari browser, that could allow an actor to execute code on a device.

“Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited,” the Cupertino-based tech giant said on Jan. 22.

Several other bugs that impact WebKit, Safari, reset services, mail, kernel (the core of an operating system), and more were fixed in the update, according to Apple’s support page.

Two WebKit issues also could lead to remote code execution, while the kernel problem could allow an attacker to execute code through an app, it said.

“For our customers’ protection, Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are available. Recent releases are listed on the Apple security releases page,” the company said.

In September, the federal cybersecurity agency directed other agencies to fix an exploit that could infect iPhones with the controversial NSO Group’s Pegasus spyware that has allegedly been used to surveil individuals in other countries as well as iPhones belonging to individuals at a Washington-based civil society organization.

The update will be automatic for many iPhone users, but it depends on their phone settings.

Users can go to the iPhone’s Settings before tapping General, then tapping Software Update to download and install iOS 17.3 (or iOS 16.7.5 or iOS 15.8.1 for older models), as well as the aforementioned security fixes. That download can be accessed regardless of whether the user has automatic updates turned on or off.

According to the company, its latest iOS and iPhone update will separately provide more crash detection optimizations for all iPhone 14 and iPhone 15 models. Apple posted its most recent update’s full release notes on its website.

联系我们 contact @ memedata.com