toggle

AAPL Stock: 112.76 ( -0.53 )

Printed from http://www.macnn.com

iOS vulnerability could allow keyboard, button logging by attackers

updated 03:43 pm EST, Tue February 25, 2014

Even patched versions of iOS 6, 7 are exposed, firm says

A vulnerability in iOS could allow remote hackers to log every keyboard and button press a person makes, says security firm FireEye. The exploit is only theoretical -- and would require a compromised app to somehow make it through the App Store review process -- but is said to have been tested and could potentially expose both software and hardware interactions. This includes Touch ID unlocks, although not the actual fingerprint data involved.

The hole is present in even the latest versions of iOS 6 and 7. A now-deleted FireEye blog post claimed that the company actually passed a proof-of-concept app through the App Store, but that it's "collaborating with Apple" on the issue.

iOS appears to be exposed to the problem through the resources it offers to apps running in the background. If so, the main way of avoiding attacks until a patch is released is simply to avoid questionable apps, or if all else fails kill their processes using the iOS task switcher.





by MacNN Staff

POST TOOLS:

TAGS :

toggle

Comments

  1. Marook

    Forum Regular

    Joined: 05-05-99

    1: 'remote hackers'?
    If at all usable, YOU need to put the App on your iDevice! There is NO remote 'hacking' in this regard!

    2: What userdata can they get? You would need to know the Locale the iOS device is running in, and then parse the _potential_ keypad keys pressed, if it's a keypad/board.. Or is there alphanumeric data in the events? Don't think so...!

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

Follow us on Facebook

toggle

Most Popular

Advertisement

Recent Reviews

ZTE Spro 2 Smart Projector

Home theaters are becoming more and more accessible these days, but maybe you've been a bit wary about buying a home projector. And h ...

MSI Geforce GTX 970 100ME

When Nvidia announced a new line of video cards in September 2014, many people thought things would continue to be business as usual i ...

Wren V5US Wireless Sound System

If you're a music fanatic, chances are you are, by extension, a bit fanatical about what you listen to your music on. If you're like ...

toggle

Most Commented