This major Apple bug could let hackers steal your photos and wipe your device

Apple’s macOS and iOS are often considered to be more secure than their rivals, but that doesn’t make them invulnerable. One security team recently proved that by showing how hackers could exploit Apple’s systems to access your messages, location data and photos, and even wipe your device entirely.

The discoveries were published on the blog of security research firm Trellix and will be of major concern to iOS and macOS users alike, since the vulnerabilities can be exploited on both operating systems. Trellix explains that Apple patched the exploits in macOS 13.2 and iOS 16.3, which were released in January 2023, so you should update your devices as soon as you can.

piranka/Getty Images

Apple protects its systems by requiring apps to be signed by approved developers, by sandboxing apps to prevent them from accessing areas they should not, and by almost entirely removing the ability to dynamically run arbitrary code. Combined, those measures help macOS and iOS become highly secure — but apparently not secure enough.

Related

  • Google Chrome’s latest update solves the browser’s biggest problem

  • We now know why Apple’s Reality Pro headset was delayed

  • Apple spring event: massive Mac launch, XR headset, and more

Trellix’s blog post explains that the infamous cyber-intelligence organization NSO Group bypassed some of these protections in 2021 by exploiting Apple’s NSPredicate system. In short, NSPredicate is one of the few elements of macOS and iOS that can dynamically generate code — something that was thought to be absent from Apple’s operating systems. NSO Group discovered this and used it to craft its Pegasus spyware.

This exploit was dubbed FORCEDENTRY, and Apple patched it shortly after its discovery in late 2021. Trellix’s work, however, has shown that Apple’s patches can be easily bypassed, rendering them useless.

In fact, Trellix claims it has found an entire class of bugs that can be exploited this way, granting hackers access to a user’s calendar, address book, photos, camera, microphone, and more. Some bugs could even be used to wipe your device in its entirety.

Trellix passed on the details of the exploits it discovered to Apple, and they were patched earlier this year. That means you should download the fixes — contained in macOS 13.2 and iOS 16.3 and later versions — as soon as you can. They also serve as a helpful reminder that, despite the company’s reputation for strong security, no Apple product is invulnerable to attack. Ensuring your device is up to date is a great way to keep it safe.

dt-daily-logo.png?fit=430%2C140&p=1

Today’s tech news, curated and condensed for your inbox

Subscribe



Check your inbox!

Please provide a valid email address to continue.

This email address is currently on file. If you are not receiving newsletters, please check your spam folder.

Sorry, an error occurred during subscription. Please try again later.

Privacy Policy

Use a different email

Related posts

Latest posts

This HP Omen gaming laptop is on sale for under $1,000

With patience, you can score a nice machine from for under $1,000. You don’t even have to do the searching yourself, as we’ve found the perfect offer for you — the HP Omen 17z gaming laptop for only $950, following a $400 discount from HP on its original price of $1,350. This device isn’t going […]

Need a new daily driver? This HP Pavilion laptop is 53% off

The HP Pavilion 16t laptop with the 13th-generation Intel Core i5 processor and 8GB of RAM is on sale for less than half-price following HP's $530 discount.

Use this code to get $50 off this 27-inch 2K gaming monitor

The 27-inch Mobile Pixels Mini-LED 2K QHD gaming monitor already offers great value at its original price of $400, but you can get it for $350 from StackSocial.

Practically all of the best Android phones are hindered by this one dumb thing

As life goes on, so might what you need from your phone. Unfortunately, you're on your own if you need

Chromecast with Google TV suffers from its long-awaited Android 14 update

Chromecast with Google TV users started reporting problems after its Android 14 update.

It’s time to say goodbye to Google Assistant as Gemini takes over

Google announced today Google Assistant will no longer be accessible on most mobile devices, in the coming months.

Google updates Find My Device with a ‘People’ tab location-sharing option

Google was spotted rolling out an update for Find My Device that brings location-sharing for people.

Apple says it will add RCS encryption to texts with Android following GSMA update

A GSMA press release announced the RCS standard will adopt encryption measures for users, Apple prepares a rollout.

CUKTECH’s 40,000mAh battery pack gives a whole new meaning to power on the go

Portable power has so many interpretations. You probably haven't seen anything like this mini 40,000mAh battery pack from CUKTECH before.

This ‘flagship-level’ and ‘exceptional’ Motorola phone is selling for a mere $250 at Amazon today

Amazon has launched a limited-time discount of 38% off the 256GB Motorola Moto G Stylus 5G, which is a solid