Showing posts with label OS X Yosemite. Show all posts
Showing posts with label OS X Yosemite. Show all posts

Thursday, 1 October 2015

Apple Close 147 Vulnerabilities In OS X, iOS And Safari


Apple yesterday updates to Mac OS X, iOS and Safari released, which fix 147 vulnerabilities added. The biggest update was for Mac OS X. OS X El Capitan (OS X 10:11) Apple also has many new features in addition to fixed 101 vulnerabilities.

Through the vulnerabilities an attacker could execute arbitrary code in the worst case. Also, it appeared to be possible to gain access to keychain items and Safari users to follow as they were using private-browsing. Furthermore, an attacker could intercept via a man-in-the-middle SSL / TLS connections, decrypt SSL traffic and determine RSA private keys.

It is now no longer possible to flash the firmware with a malignant Ethernet Apple Thunderbolt adapter. In addition, it appeared that the "Secure Empty Trash" option to permanently delete files, deleted files are not always permanent. A list of all solved problems on the website of Apple to find. The new OS X version can be downloaded via the Mac App Store and Apple.com.

IOS

Yesterday released a new version of iOS. IOS 9.0.2 fixes a vulnerability allowing someone with physical access to the device photos and contacts could approach, even though the screen lock was active. Due to a problem with the lock screen could these data and files are still accessed. Apple has solved this by limiting the options available on a locked device. The update can be downloaded via iTunes and the Software Update feature.

Safari

In Safari 9 for OS X Mavericks, OS X Yosemite and El Capitan OS X, Apple has fixed 45 vulnerabilities. Through the vulnerabilities an attacker could determine the browsing history of users and Safari Extensions replaced. Due to a problem with the Safe Browsing option users were not warned when they visited a known malicious website. In the worst case, an attacker could execute when visiting a hacked or malicious website arbitrary code on the system. Safari 9 can be downloaded via the Mac App Store.

Thursday, 2 July 2015

Apple Closed 164 Vulnerabilities In OS X, iOS, Safari, iTunes, And QuickTime


Apple yesterday evening updates for Mac OS X, iOS, Safari, iTunes, QuickTime, and Mac EFI released that fix vulnerabilities 164 together. Most of the updates, 77 in total, appeared for Mac OS X in the form of OS X Yosemite 10.10.4 and Security Update 2015-005 .

Thus, clearing the logjam attack through these updates, as well as several vulnerabilities which could allow an attacker at worst arbitrary code on the computer. This could for instance by the user to open a malicious zip file. The updates can be downloaded via the Mac App Store or Apple's download site.

IOS

In iOS 8.4 , Apple fixed 33 security vulnerabilities. Through the vulnerabilities could allow an attacker who is between the user and the Internet was to intercept network traffic, execute arbitrary code, external HTML in the Mail app loading, accounts taken over by users to a malicious website visits or perform the logjam attack. For arbitrary code execution, an attacker could use a malicious SIM card. Updating to iOS 8.4 can automatically or manually via iTunes or the Software Update feature.

Safari and Mac EFI

Apple also released new versions of Safari. Safari 8.0.7, Safari 7.1.7 and Safari 6.2.7 fix four vulnerabilities allowing a malicious website could approach the WebSQL database from other websites, visiting a specially prepared website made ​​it possible to hijack accounts, there via a malicious link to a PDF file was embedded in a website cookies could be stolen and the worst could be executed arbitrary code when visiting a malicious website. Updating via the Mac App Store.

Apple also patched the leak making it possible via a malicious app with root privileges EFI firmware to match. Furthermore, among the Rowhammer attack, which investigators DDR3 memory could attack the past. Also EFI Mac Security Update 2015-001 is available via the Mac App Store.

Windows Users

For Windows users also appeared updates. These are patches for QuickTime and iTunes for Windows. iTunes 12.2 for Windows 7 and Windows 8 fixes 39 vulnerabilities could allow an attacker, who was between the user and the Internet, could execute arbitrary code on the computer and the iTunes Store was visited. In QuickTime was the execution of arbitrary code.This, however, had to be opened a specially prepared file. The nine leaks in QuickTime 7.7.7 corrected.

Tuesday, 27 January 2015

Apple: "Thunderbolt Attack In OS X Patch"


Apple will soon release an update for Mac OS X Yosemite discovered next three vulnerabilities revealed by Google and also the last year demonstrated Thunderbolt attack will remedy. Let sources with access to the beta version of Mac OS X 10.10.2 opposite iMore know.

In late December showed researcher Trammell Hudson during the CCC hacker conference in Hamburg how he bootkit can install on an Apple Macbook that reinstalling the operating system and replace the hard drive can survive through the Thunderbolt port. Once the bootkit is running that can spread virally by infecting other Thunderbolt devices.

To install the bootkit is need physical access to the computer. To adjust Mac computers to protect against the attack Apple had not only the code that prevents the boot ROM is replaced, but that a rollback to a previous state which prevented the attack still works.

Further, Mac OS X, 10.10.2 Yosemite also three vulnerabilities remedy that Google recently revealed in the OS.Researchers from the search giant had vulnerabilities discovered last year and reported to Apple. Since they are not within the Apple patched the details were automatically made ​​public time limits provided by Google. Something happened earlier vulnerabilities in Microsoft.