<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ios bug Archives - Linux Windows and android Tutorials</title>
	<atom:link href="https://www.osradar.com/tag/ios-bug/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osradar.com</link>
	<description>tutorials and news and Seurity</description>
	<lastBuildDate>Mon, 17 Sep 2018 13:05:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.8.13</generator>
	<item>
		<title>CSS Attacks to Restart iPhone or Freeze a Mac</title>
		<link>https://www.osradar.com/css-attacks-to-restart-iphone-or-freeze-a-mac/</link>
					<comments>https://www.osradar.com/css-attacks-to-restart-iphone-or-freeze-a-mac/#respond</comments>
		
		<dc:creator><![CDATA[osradar_editor]]></dc:creator>
		<pubDate>Mon, 17 Sep 2018 13:05:09 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[apple. apple broken]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ios bug]]></category>
		<category><![CDATA[ios glitch]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[macos bug]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=5860</guid>

					<description><![CDATA[<p>Security is something that that must stay safe all the time, no matter the cost, right? When we first heard about Meltdown and Spectre, we went as far as to disable the cool (dangerous?) features that even slowed our systems down. Now, even the iOS and macOS is susceptible to attacks! Yes, that’s a fact. [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/css-attacks-to-restart-iphone-or-freeze-a-mac/">CSS Attacks to Restart iPhone or Freeze a Mac</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Security is something that that must stay safe all the time, no matter the cost, right? When we first heard about Meltdown and Spectre, we went as far as to disable the cool (dangerous?) features that even slowed our systems down. Now, even the iOS and macOS is susceptible to attacks! Yes, that’s a fact.</p>
<p>We all knew that Apple is the top-class company when we talk about security, right? Now, researchers were able to find out a way to make sure that you would face a glitch while visiting specific websites. These websites only use HTML and CSS.</p>
<p>Jokes aside, let’s get to the real news.</p>
<h1>CSS to restart iOS and freeze macOS</h1>
<p><img loading="lazy" class="wp-image-5861 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/09/freeze.jpg" alt="" width="712" height="446" srcset="https://www.osradar.com/wp-content/uploads/2018/09/freeze.jpg 500w, https://www.osradar.com/wp-content/uploads/2018/09/freeze-300x188.jpg 300w" sizes="(max-width: 712px) 100vw, 712px" /></p>
<p>It’s sort of surprising, but security researchers were able to perform attacks using HTML and CSS only on iOS and macOS. Fortunately, Windows and Linux users are not affected by the issue. Sabri Haddouche, a security researcher at Wire, discovered this new attack. Using this technique, he was able to quickly hog up all the resources of Apple devices.</p>
<p>According to Haddouche, the weakness lies in the “-webkit-backdrop-filter” CSS property. Using nested DIVS with that property, it’s easily possible to consume all the graphic resources and crash/freeze the OS. There’s no necessity to JavaScript. That’s why it successfully works on other places like Mail.</p>
<p>Unfortunately, iOS is the most susceptible to this attack as well as Safari and Mail in macOS. All of them use the WebKit rendering engine.</p>
<p>Depending on the version of iOS, the attack may cause a UI restart or even a kernel panic and a device reboot. As a demo, Haddouche performed this attack on an iOS 12 and the device rebooted completely whereas an iOS 11.4.1 caused a respring.</p>
<h1>Visit a web page and get attacked!</h1>
<p><img loading="lazy" class="size-full wp-image-5862 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/09/cyber-attack.jpg" alt="" width="1000" height="681" srcset="https://www.osradar.com/wp-content/uploads/2018/09/cyber-attack.jpg 1000w, https://www.osradar.com/wp-content/uploads/2018/09/cyber-attack-300x204.jpg 300w, https://www.osradar.com/wp-content/uploads/2018/09/cyber-attack-768x523.jpg 768w, https://www.osradar.com/wp-content/uploads/2018/09/cyber-attack-696x474.jpg 696w, https://www.osradar.com/wp-content/uploads/2018/09/cyber-attack-617x420.jpg 617w" sizes="(max-width: 1000px) 100vw, 1000px" /></p>
<p>The attack doesn’t require anything especial trick; just only visiting a special CSS and HTML website is more than enough. Here’s the perfect demo of the attack.</p>
<p>Unfortunately, there’s currently no mitigation or solve to this problem. You can keep yourself safe by following basic safety rules like not clicking any random link. The fix will eventually come, though. So, stay sharp!</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/css-attacks-to-restart-iphone-or-freeze-a-mac/">CSS Attacks to Restart iPhone or Freeze a Mac</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/css-attacks-to-restart-iphone-or-freeze-a-mac/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ZipperDown Infecting iOS Apps</title>
		<link>https://www.osradar.com/zipperdown-infecting-ios-apps/</link>
					<comments>https://www.osradar.com/zipperdown-infecting-ios-apps/#respond</comments>
		
		<dc:creator><![CDATA[Mel]]></dc:creator>
		<pubDate>Fri, 18 May 2018 03:38:53 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[android bug]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ios app]]></category>
		<category><![CDATA[ios bug]]></category>
		<category><![CDATA[ios vulnerability]]></category>
		<category><![CDATA[zipperdown]]></category>
		<guid isPermaLink="false">https://www.osradar.com/?p=3146</guid>

					<description><![CDATA[<p>iOS is supposed to be one of the toughest platforms for security. Apple designed it really good for being smooth and secured at the same time. However, a new vulnerability is found in the iOS apps that infect almost 10% of all the iOS apps all over the world. Security researchers from Pangu Lab, a [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/zipperdown-infecting-ios-apps/">ZipperDown Infecting iOS Apps</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>iOS is supposed to be one of the toughest platforms for security. Apple designed it really good for being smooth and secured at the same time. However, a new vulnerability is found in the iOS apps that infect almost 10% of all the iOS apps all over the world.</p>
<p>Security researchers from Pangu Lab, a well-known company for providing jailbreaks have confirmed the vulnerability and named it “ZipperDown”. This flaw, according to their description, is a common programming error that leads to severe consequences like data overwriting, even code execution in the affected apps’ context.</p>
<h3>Vulnerable apps</h3>
<p><img loading="lazy" class="size-full wp-image-3148 aligncenter" src="https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android.png" alt="" width="1250" height="455" srcset="https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android.png 1250w, https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android-300x109.png 300w, https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android-768x280.png 768w, https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android-1024x373.png 1024w, https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android-696x253.png 696w, https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android-1068x389.png 1068w, https://www.osradar.com/wp-content/uploads/2018/05/zipperdown-bug-ios-android-1154x420.png 1154w" sizes="(max-width: 1250px) 100vw, 1250px" /></p>
<p>Pangu Lab created a scan rule for searching ZipperDown flaw in iOS apps. According to the result, 15,978 out of 168,951 scanned apps appear to have ZipperDown infection. However, they also added that the apps are to be manually inspected for confirmation.</p>
<p>Unfortunately, in the list of vulnerable apps, there are some really popular apps like NetEase Music, QQ Music, MOMO, Kwai etc. who have over 100 million users. Here’s a video where the researchers showed a demo infecting Weibo.</p>
<h3>Devs must contact the researchers</h3>
<p>Pangu Lab said that due to the potential infection in a large amount of apps, they’re not able to verify all the individual apps precisely. Moreover, the number of authors of infected apps is also large enough, making it really difficult for contacting each of them and informing the issue.</p>
<p>That’s why the company is asking the devs if their apps is on the list of potential infection list, they need to contact Pangu Lab for further details and test &amp; fix their application(s).</p>
<h3>Android infected(?)</h3>
<p>According to Pangu Lab, Android also suffers from similar issues like ZipperDown. The researchers said that they’ll continue further investigation for pinning the flaw.</p>
<p>Fortunatley, ZipperDown isn’t like other vulnerabilities and not available for easy exploitation. In order to exploit, the hacker must be within the range of the same network position for hijacking/spoofing traffic. According to the researchers, the sandbox on both Android and iOS are really effective in mitigating any possible damage for ZipperDown’s consequences.</p>
<h3>How to stay secured</h3>
<p>If you want to protect yourself from the vulnerability, you have to make sure that you are using the latest version of all the installed apps. It’s highly likely that app devs will release update to their software in the future.</p>
<p>Recently, the source code of TreasureHunter malware went public. Learn more about <a href="https://www.osradar.com/treasurehunter-pos-malware-source-code-published/">the source code leak and the future attacks</a>.</p>
<p>The post <a rel="nofollow" href="https://www.osradar.com/zipperdown-infecting-ios-apps/">ZipperDown Infecting iOS Apps</a> appeared first on <a rel="nofollow" href="https://www.osradar.com">Linux  Windows and android  Tutorials</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.osradar.com/zipperdown-infecting-ios-apps/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
