Security Bug Makes Millions Of iOS 8.3 iCloud Passwords Vulnerable

Kullanıcı1233

Kıdemli Üye
19 Tem 2011
4,371
12
You may need to change the password of your iOS device as a security researcher reported that a flaw in Apple’s systems can let hackers send iCloud users phishing emails, making millions of accounts vulnerable.

Jan Soucek (@jansoucek), a white hat hacker or someone who uses his technical skills for good purposes not evil, developed an iOS8.3 mail.app popup, which resembles the sort of messages sent normally by Apple users when they are asked to submit their password. However, instead of offering the iCloud user access to the account the popup lets hackers gain control of the targeted computer, Soucek says.

apple-security-bug-ios-icloud-passwords.jpg



The presence of any such security bug hasn’t been verified by Apple but the firm didn’t reply Soucek when he reported this issue.

Soucek attached a video footage about how the hack attack can be conducted and wrote on a GitHub page that:

“THIS BUG ALLOWS REMOTE HTML CONTENT TO BE LOADED, REPLACING THE CONTENT OF THE ORIGINAL EMAIL MESSAGE. JAVASCRIPT IS DISABLED IN THIS UIWEBVIEW, BUT IT IS STILL POSSIBLE TO BUILD A FUNCTIONAL PASSWORD ‘COLLECTOR’ USING SIMPLE HTML AND CSS.”
Nonetheless, the iPhone/iPad maker is yet to confirm the vulnerability and also, none of the iCloud users have been affected by this bug. But, we can conclude this is may prove to be another headache for the iCloud that has already been exploited a lot previous year when hundreds of nude photos of celebrities got leaked.

Watch the video uploaded by hacker below:

https://www.hackread.com/apple-security-bug-ios-icloud-passwords/
 
Üst

Turkhackteam.org internet sitesi 5651 sayılı kanun’un 2. maddesinin 1. fıkrasının m) bendi ile aynı kanunun 5. maddesi kapsamında "Yer Sağlayıcı" konumundadır. İçerikler ön onay olmaksızın tamamen kullanıcılar tarafından oluşturulmaktadır. Turkhackteam.org; Yer sağlayıcı olarak, kullanıcılar tarafından oluşturulan içeriği ya da hukuka aykırı paylaşımı kontrol etmekle ya da araştırmakla yükümlü değildir. Türkhackteam saldırı timleri Türk sitelerine hiçbir zararlı faaliyette bulunmaz. Türkhackteam üyelerinin yaptığı bireysel hack faaliyetlerinden Türkhackteam sorumlu değildir. Sitelerinize Türkhackteam ismi kullanılarak hack faaliyetinde bulunulursa, site-sunucu erişim loglarından bu faaliyeti gerçekleştiren ip adresini tespit edip diğer kanıtlarla birlikte savcılığa suç duyurusunda bulununuz.