Apple patches iPhone exploit that allowed for ‘extremely sophisticated' attack

A new iPhone update patches a flaw that could allow an attacker to turn off a nearly seven-year-old USB security feature. Apple’s release notes for iOS 18.3.1 and iPadOS 18.3.1 say the bug, which allowed the deactivation of USB Restricted Mode, “may have been exploited in an extremely sophisticated attack against specific targeted individuals.”

The release notes describe the now-patched security flaw as allowing “a physical attack,” which suggests the attacker needed the device in hand to exploit it. So, unless your device was hijacked by “extremely sophisticated” attackers, there was nothing to panic about even before Monday’s update.

USB Restricted Mode, introduced in iOS 11.4.1, prevents USB accessories from accessing your device’s data if it hasn’t been unlocked for an hour. The idea is to protect your iPhone or iPad from law enforcement devices like Cellebrite and Graykey. It’s also the reason for the message asking you to unlock your device before connecting it to a Mac or Windows PC.

Aligned with its typical policy, Apple didn’t detail who or what entity used the attack in the wild, only noting that the company is “aware of a report that this issue may have been exploited.” Security researcher Bill Marczak of the University of Toronto’s Citizen Lab reported the flaw. In 2016, while in grad school, he discovered the iPhone’s first known zero-day remote jailbreak, which a cyberwarfare company sold to governments.

You can make sure USB Restricted Mode is activated by heading to Settings > Face ID (or Touch ID) & Passcode. Scroll down to “Accessories” in the list and ensure the toggle is off, which it is by default. Somewhat confusingly, toggling the setting off means the security feature is on because it lists features with allowed access.

As usual, you can install the update by heading to Settings > General > Software Update on your iPhone or iPad.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/apple-patches-iphone-exploit-that-allowed-for-extremely-sophisticated-attack-214237852.html?src=rss https://www.engadget.com/cybersecurity/apple-patches-iphone-exploit-that-allowed-for-extremely-sophisticated-attack-214237852.html?src=rss
Creată 8h | 10 feb. 2025, 22:50:28


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

Elon Musk wants to buy OpenAI for $97.4 billion

Elon Musk has launched a $97.4 billion bid to take control of OpenAI.

10 feb. 2025, 22:50:27 | Engadget
Lyft aims for a 2026 Dallas launch of its first Mobileye robotaxis

Lyft is scrambling to compete as Uber racks up auton

10 feb. 2025, 20:30:25 | Engadget
Roblox, Discord, OpenAI and Google found new child safety group

Roblox, Discord, OpenAI and Google are launching

10 feb. 2025, 20:30:24 | Engadget
The OnePlus Watch 3 arrives on February 18

OnePlus has revealed that you'll be able to get your hands on (or wrist under) its latest smartwatch very soon. The OnePlus Watch 3 will be available in the US, Canada and Europe on February 18. Th

10 feb. 2025, 18:20:10 | Engadget
France pledges to build one gigawatt of new nuclear to speed up its AI ambitions

It's France's turn to get in on the AI boom. On Sund

10 feb. 2025, 15:50:21 | Engadget
The USB-C Apple Pencil is back on sale for $69

Apple currently has four different Apple Pencil models, and if you aren’t sure which one to get, try reading this

10 feb. 2025, 15:50:20 | Engadget
Two years of NordPass Premium is 56 percent off right now

Having thought-out, unique passwords for each account is hard — recently, I got stopped for putting the same letter twice in a row — especially when it comes to remembering them all. That's why a

10 feb. 2025, 15:50:18 | Engadget