ZipperDown: Remote Code Execution Attack on iOS Apps

On May 15, 2018, Pangu Lab announced the ZipperDown vulnerability, which allows a remote code execution attack on iOS apps. Although Pangu Lab did not disclose the details of the ZipperDown vulnerability, we can infer from its researcher’s public… Continue reading ZipperDown: Remote Code Execution Attack on iOS Apps

ZipperDown Programming Vulnerability Could Let Hackers Execute Code in iOS Apps

A recently discovered vulnerability in iOS applications could allow hackers to execute code within affected apps, provided the device is connected to an attacker-controlled Wi-Fi network. The number of potentially vulnerable applications is estimated a… Continue reading ZipperDown Programming Vulnerability Could Let Hackers Execute Code in iOS Apps

QR Code Bug In iOS 11 Tricks Camera App to Open Unpredictable Websites

A recent vulnerability in the way Apple’s iOS camera app handles automatic QR code scanning, could potentially be abused to trick users into opening potentially nasty websites, according to security researchers. The bug is triggered whenever user… Continue reading QR Code Bug In iOS 11 Tricks Camera App to Open Unpredictable Websites

Millions of Android Devices Using Broadcom Wi-Fi Chip Can Be Hacked Remotely

Google has released its latest monthly security update for Android devices, including a serious bug in some Broadcom Wi-Fi chipsets that affects millions of Android devices, as well as some iPhone models.

Dubbed BroadPwn, the critical remote code exec… Continue reading Millions of Android Devices Using Broadcom Wi-Fi Chip Can Be Hacked Remotely

iOS 9.3.4 Patches Critical Code Execution Flaw

Apple patched a critical iOS memory corruption vulnerability privately disclosed by jailbreak specialists Pangu Team. Continue reading iOS 9.3.4 Patches Critical Code Execution Flaw

For the First time, FBI discloses a Flaw to Apple, but it’s already Patched!

In Brief
The Federal Bureau of Investigation (FBI) made its first disclosure about a software security flaw to Apple under the Vulnerability Equities Process (VEP), a White House initiative created in April 2014 for reviewing flaws and deciding which ones should be made public.

Unfortunately, the vulnerability reported by the federal agency only affected older versions of Apple’s iOS and OS

Continue reading For the First time, FBI discloses a Flaw to Apple, but it’s already Patched!

SideStepper Allows for MiTM Between iOS Devices, MDM Tools

Check Point has discovered a weakness that allows hackers to use phishing to carry out man-in-the-middle attacks between iOS devices and mobile device management tools and allow an attacker to push malicious apps to devices. Continue reading SideStepper Allows for MiTM Between iOS Devices, MDM Tools