Your Web News in One Place

Help Webnuz

Referal links:

Sign up for GreenGeeks web hosting
January 12, 2022 08:11 pm GMT

Apple releases iOS 15.2.1 to patch a serious HomeKit DDoS vulnerability

Apple has released iOS 15.2.1, its latest software update for recent iPhone and iPad devices. The patch addresses a vulnerability found within the companys HomeKit protocol for connecting disparate smart home devices. The bug allowed malicious individuals to force an iPhone or iPad to repeatedly crash and freeze by changing the name of a HomeKit-compatible device to include more than 500,000 characters. Since iOS backs up HomeKit device names to iCloud, it was possible for iOS users to get stuck in an endless loop of crashes.

Security researcher Trevor Spiniolas discovered the vulnerability and publicly disclosed it on January 1st. According to Spiniolas, he informed Apple of the bug back in August. The company had reportedly planned to address the vulnerability before the end of 2022 but later delayed a fix to early 2022. I believe this bug is being handled inappropriately as it poses a serious risk to users and many months have passed without a comprehensive fix, Spiniolas said at the time.

Spiniolas found that the vulnerability is present within Apples mobile operating system as far back as iOS 14.7, but said he believes it exists in all versions of iOS 14. In other words, if youve been holding off on installing iOS 15, now is the time to update your Apple devices.


Original Link: https://www.engadget.com/ios-15-2-1-homekit-vulerability-fix-201158978.html?src=rss

Share this article:    Share on Facebook
View Full Article

Engadget

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics. Engadget was launched in March of 2004 in partnership with the Weblogs, Inc. Network (WI

More About this Source Visit Engadget