ZeroHour
Security Affairspublished ()ingested @securityaffairs

Upgrade to iOS 10.1 or you can get hacked by opening a JPEG or a PDF

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-4677
+2 in the same advisory: …4673 …4686
An issue was discovered in certain Apple products.

An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

NVD description · AI analysis pending
8.8
group max
2%
  • apple iphone os
  • apple safari
  • apple tvos
Full article308 words · extracted from securityaffairs.com · click to collapse

Viewing a maliciously crafted JPEG may lead to arbitrary code execution, a boobytrapped JPEG could compromise your iPhone. Upgrade to iOS 10.1

Even a simple action such as looking a JPEG image or opening a PDF document could cause serious problems, an attacker, in fact, could hijack your Apple mobile device (iPhone, iPad, and iPod).

Yes, it’s correct! A booby trapped JPEG image could compromise your vulnerable iPhone remotely.

The Apple devices are affected by a critical remote-code execution flaw, tracked as CVE-2016-4673, for this reason, the tech giant has released a new version of its mobile operating system, iOS 10.1, that addressed the issue alongside other bugs. Below the description of the flaw provided by Apple.

iOS 10.1

CoreGraphics

Available for: iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation and later

Impact: Viewing a maliciously crafted JPEG file may lead to arbitrary code execution

Description: A memory corruption issue was addressed through improved memory handling.
CVE-2016-4673: Marco Grassi (@marcograss) of KeenLab (@keen_lab), Tencent

As usually happens in these cases, it is crucial a rapid patch management, users have to update their OS to fix the problems. Unfortunately, this is not true and hackers worldwide could take control of the vulnerable Apple devices in a very simple way.

The newest iOS 10.1 includes also other security updates that address 11 security flaws in the firmware for the iPhone, iPad, and iPod Touch.

The list of vulnerabilities fixed with the iOS 10.1 release includes a local code execution vulnerability, a vulnerability in contacts (CVE-2016-4686), a remote code execution flaw in WebKit (CVE-2016-4677).

Don’t waste time, update your mobile devices to the iOS 10.1 release as soon as possible.

To update your iOS device go to Settings General Software Update.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs – iOS 10.1, Iphone)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/52701/hacking/ios-10-1-hacking.html