<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>security flaw Archives - Gizmochina</title>
	<atom:link href="https://www.gizmochina.com/tag/security-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.gizmochina.com/tag/security-flaw/</link>
	<description>Latest Tech News, Product Reviews and Deals</description>
	<lastBuildDate>Wed, 06 Dec 2023 08:52:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.9</generator>
	<item>
		<title>Nothing&#8217;s CMF Watch app suffers from a security vulnerability: Report</title>
		<link>https://www.gizmochina.com/2023/12/06/nothings-cmf-watch-app-suffer-security-vulnerability/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Wed, 06 Dec 2023 08:52:39 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Nothing]]></category>
		<category><![CDATA[CMF Watch Pro]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=588311</guid>

					<description><![CDATA[<img width="300" height="257" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-300x257.png?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="CMF Watch Pro" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-300x257.png 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-1024x878.png 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-768x658.png 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-696x596.png 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-490x420.png 490w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435.png 1049w" sizes="(max-width: 300px) 100vw, 300px" /><p>A couple of months ago, Nothing unveiled its new sub-brand CMF, which released a bunch of new products. This included the CMF Watch Pro model. However, it appears that a security vulnerability plagues the CMF Watch app that is featured on the partnered smartphone. CMF Watch App may lack encryption, posing a security risk The [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/12/06/nothings-cmf-watch-app-suffer-security-vulnerability/">Nothing&#8217;s CMF Watch app suffers from a security vulnerability: Report</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="257" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-300x257.png?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="CMF Watch Pro" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-300x257.png 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-1024x878.png 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-768x658.png 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-696x596.png 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-490x420.png 490w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435.png 1049w" sizes="(max-width: 300px) 100vw, 300px" />
<p>A couple of months ago, <a href="https://www.gizmochina.com/tag/nothing/" target="_blank" rel="noreferrer noopener">Nothing </a>unveiled its new sub-brand <a href="https://www.gizmochina.com/tag/cmf/" target="_blank" rel="noreferrer noopener">CMF</a>, which released a bunch of new products. This included the <a href="https://www.gizmochina.com/tag/cmf-watch-pro/" target="_blank" rel="noreferrer noopener">CMF Watch Pro</a> model. However, it appears that a security vulnerability plagues the CMF Watch app that is featured on the partnered smartphone. </p>



<h2>CMF Watch App may lack encryption, posing a security risk</h2>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-1024x878.png?x23692" alt="CMF Watch Pro" class="wp-image-570011" width="659" height="565" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-1024x878.png 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-300x257.png 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-768x658.png 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-696x596.png 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435-490x420.png 490w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-26-171435.png 1049w" sizes="(max-width: 659px) 100vw, 659px" /></figure></div>



<p>The news was shared by Dylan Roussel, who is an Android developer. In a tweet, the dev claimed that Nothing is garnering attention for its glary security risks. He adds that the latest example of a vulnerability in their system comes from their new sub-brand, CMF. Apparently, the company&#8217;s CMF Watch app suffers from a major security flaw that is related to the encryption of user data. The investigations have revealed that the brand&#8217;s encryption process for the user&#8217;s email address and password is not functioning properly.</p>



<p>This means that the sensitive information is at risk. Dylan adds that the major security risk is still affecting the CMF Watch app, with user&#8217;s login credentials still being vulnerable. Nothing&#8217;s current app system lacks robust encryption for sensitive information, enabling easy access to decryption data with the application. This vulnerability was first discovered by Roussel back in September.</p>



<p><blockquote class="twitter-tweet" data-width="550" data-dnt="true"><p lang="en" dir="ltr">Let&#39;s talk about Nothing&#8230; again. <br><br>Before the Sunbird/Nothing chaos, I reported another vulnerability to them back in September&#8230; and another one back in August.<br><br>Let&#39;s talk about the one from September. It&#39;s about the CMF Watch app.</p>&mdash; Dylan Roussel (@evowizz) <a href="https://twitter.com/evowizz/status/1730619959246569769?ref_src=twsrc%5Etfw">December 1, 2023</a></blockquote><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>



<p>Nothing has worked on fixing this issue, but it seems that the encryption for the email and password are still vulnerable. The Android developer had even reached out to the brand directly, although there was no proper communication established after the first exchange. It remains to be seen how the company addresses these glaring security risks or whether it continues to become infamous for security flaws, since even the Nothing Chats feature was <a href="https://www.gizmochina.com/2023/11/19/nothing-chats-removed-from-play-store-over-security-concerns/" target="_blank" rel="noreferrer noopener">recently removed </a>from the Google Play Store over security concerns.</p>



<p><strong>RELATED:</strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/12/06/nothing-apparel-labcoat-cap-launched-with-transparent-design-heres-when-how-to-purchase-them/" target="_blank" rel="noreferrer noopener">Nothing Apparel Labcoat, Cap launched with transparent design, here’s when how to purchase them</a></li><li><a href="https://www.gizmochina.com/2023/11/19/nothing-chats-removed-from-play-store-over-security-concerns/" target="_blank" rel="noreferrer noopener">‘Nothing Chats’ removed from Play Store over security concerns</a></li><li><a href="https://www.gizmochina.com/2023/11/07/get-100-off-on-lenovo-legion-y700-2023-gamin-tablet-at-giztop/">Lenovo Legion Y700 2023: Save $100 on this 8-inch gaming Android tablet</a></li><li><a href="https://www.gizmochina.com/2023/11/27/get-xiaomi-13-ultra-premium-5g-phone-for-as-low-as-799-at-giztop/">Xiaomi 13 Ultra Premium Camera Phone is now only $799</a></li><li><a href="https://www.gizmochina.com/2023/11/15/get-the-latest-xiaomi-14-smartphone-for-599-at-geekwills/">Xiaomi 14: New flagship with snapdragon 8 gen 3 only for $599</a></li><li><a href="https://www.gizmochina.com/guides/best-apple-watch-cases-in-2023-spigen-otterbox-casetify-more%ef%bf%bc/">Best Apple Watch Cases in 2023: Spigen, Otterbox, Casetify &amp; More</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="vivo X100 Pro Full Review: The Best Camera Phone?" width="696" height="392" src="https://www.youtube.com/embed/wFdgCKH1fHs?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/12/06/nothings-cmf-watch-app-suffer-security-vulnerability/">Nothing&#8217;s CMF Watch app suffers from a security vulnerability: Report</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple releases iOS 16.5.1 update to address security flaws</title>
		<link>https://www.gizmochina.com/2023/06/22/apple-releases-ios-16-5-1-update-address-security-flaws/</link>
		
		<dc:creator><![CDATA[Soumyakanti]]></dc:creator>
		<pubDate>Thu, 22 Jun 2023 09:31:04 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 16.5.1]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[software update]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=546349</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-300x169.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="iOS-16.5" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1536x864.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-2048x1152.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-696x391.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1920x1080.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-747x420.jpg 747w" sizes="(max-width: 300px) 100vw, 300px" /><p>Apple has recently rolled out the iOS 16.5.1 update, aiming to fix critical security vulnerabilities discovered in the previous version. The security flaws were reportedly exploited to hack iPhones in Russia. The cybersecurity firm Kaspersky brought these issues to Apple&#8217;s attention, for which the company expressed gratitude. What&#8217;s New in iOS 16.5.1 Update? One of [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/06/22/apple-releases-ios-16-5-1-update-address-security-flaws/">Apple releases iOS 16.5.1 update to address security flaws</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-300x169.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="iOS-16.5" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1536x864.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-2048x1152.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-696x391.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1920x1080.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-747x420.jpg 747w" sizes="(max-width: 300px) 100vw, 300px" />
<p><a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noreferrer noopener">Apple</a> has recently rolled out the iOS 16.5.1 update, aiming to fix critical security vulnerabilities discovered in the previous version. The security flaws were reportedly exploited to hack iPhones in Russia. The cybersecurity firm Kaspersky brought these issues to Apple&#8217;s attention, for which the company expressed gratitude.</p>



<figure class="wp-block-image size-large"><img loading="lazy" width="1024" height="576" src="https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1024x576.jpg?x23692" alt="iOS-16.5" class="wp-image-546359" srcset="https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1536x864.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-2048x1152.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-696x391.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-1920x1080.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/06/iOS-16.5-747x420.jpg 747w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption>Credit: MacRumors</figcaption></figure>



<h2>What&#8217;s New in iOS 16.5.1 Update?</h2>



<p>One of the security flaws allowed an app to execute arbitrary code with kernel privileges. Apple acknowledged that this issue may have been actively exploited on <a href="https://www.gizmochina.com/tag/ios/" target="_blank" rel="noreferrer noopener">iOS</a> versions released prior to iOS 15.7. The second vulnerability was related to Webkit, where processing malicious web content could lead to arbitrary code execution.</p>



<p>In addition to the security fixes, the update addresses an <a href="https://www.gizmochina.com/2023/05/22/apple-ios-update-breaks-dongle-adapter/" target="_blank" rel="noreferrer noopener">accessory issue introduced in iOS 16.5</a>. The problem impacted users who relied on Apple&#8217;s Lightning to USB 3 Camera Adapter to charge their iPhones. With this update, users can now resume using the accessory as intended. Apple&#8217;s release notes mention that the update is recommended for all users and provides important security improvements.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="473" height="1024" src="https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-473x1024.png?x23692" alt="iOS 16.5.1" class="wp-image-546357" srcset="https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-473x1024.png 473w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-139x300.png 139w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-768x1662.png 768w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-710x1536.png 710w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-946x2048.png 946w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-696x1506.png 696w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-1068x2311.png 1068w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065-194x420.png 194w, https://www.gizmochina.com/wp-content/uploads/2023/06/IMG_4065.png 1170w" sizes="(max-width: 473px) 100vw, 473px" /></figure></div>



<p>Alongside iOS 16.5.1, Apple has released corresponding updates for other devices, including <a href="https://www.gizmochina.com/tag/ipados/" target="_blank" rel="noreferrer noopener">iPadOS</a> 16.5.1, <a href="https://www.gizmochina.com/tag/watchos/" target="_blank" rel="noreferrer noopener">watchOS</a> 9.5.2, and <a href="https://www.gizmochina.com/tag/macos/" target="_blank" rel="noreferrer noopener">macOS</a> Ventura 13.4.1. The iPad update specifically addresses the Lightning to USB 3 Camera Adapter bug, while all the updates provide general security enhancements and resolve various issues.</p>



<p>To ensure the security and optimal performance of your Apple devices, it is recommended to update to the latest available software versions promptly. The updates are accessible through the Settings app by following these steps:</p>



<ul><li>Launch the Settings app.</li><li>Go to the General section.</li><li>Tap on Software Update.</li><li>Wait for the page to refresh.</li><li>The update will appear.</li><li>Tap on Download and Install.</li><li>Read and agree to the Terms of Service.</li><li>Keep your device connected to a power source until the update is complete.</li></ul>



<p>It is worth noting that if the initial <a href="https://www.gizmochina.com/tag/ios-17/" target="_blank" rel="noreferrer noopener">iOS 17</a> and <a href="https://www.gizmochina.com/2023/06/06/apple-unveils-macos-14-sonoma/" target="_blank" rel="noreferrer noopener">macOS Sonoma</a> betas do not include these publicly released patches, they are expected to be included in beta 2, which could be released soon.</p>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/06/22/apple-iphone-se-not-launch-2024/">Apple iPhone SE 4 may not launch next year either</a></li><li><a href="https://www.gizmochina.com/2023/06/22/apple-self-repair-program-eligeble-devices/">Apple’s Self-Repair Program Goes Next-Level: Now You Can Fix Your iPhone 14 Yourself</a></li><li><a href="https://www.gizmochina.com/2023/06/21/apple-beats-studio-pro-receives-fcc-imda-certification/">Apple Beats Studio Pro receives FCC, IMDA certification</a></li><li><a href="https://www.gizmochina.com/guides/best-vr-games-2023-the-ultimate-list-of-virtual-adventures-and-experiences/">Best VR Games 2023: The Ultimate List of Virtual Adventures and Experiences</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="IIIF150 Raptor Review: The best charger for free!" width="696" height="392" src="https://www.youtube.com/embed/eAJsCrc5VyY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://support.apple.com/en-gb/HT201222" target="_blank" rel="noreferrer noopener">Source</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/06/22/apple-releases-ios-16-5-1-update-address-security-flaws/">Apple releases iOS 16.5.1 update to address security flaws</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPhone, iPads face new vulnerabilities in latest iOS &#038; iPadOS</title>
		<link>https://www.gizmochina.com/2022/10/27/apple-ipad-iphone-security-vulnerability/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 27 Oct 2022 11:00:14 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iOS 16]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPadOS 16]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=492603</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Apple" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x.jpg 1312w" sizes="(max-width: 300px) 100vw, 300px" /><p>Apple recently released the new iOS 16.1 and iPadOS 16.1 updates for its iPhones and iPads. New updates usually bring some small bugs and glitches, but this time aaround, it appears that the new updates also come with some serious security flaws as well. According to an Economic Times report, iPhone and iPads have been [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/10/27/apple-ipad-iphone-security-vulnerability/">Apple iPhone, iPads face new vulnerabilities in latest iOS &amp; iPadOS</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Apple" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x.jpg 1312w" sizes="(max-width: 300px) 100vw, 300px" />
<p><a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noreferrer noopener">Apple </a>recently released the new iOS 16.1 and iPadOS 16.1 updates for its iPhones and iPads. New updates usually bring some small bugs and glitches, but this time aaround, it appears that the new updates also come with some serious security flaws as well.</p>



<p>According to an <em><a href="https://telecom.economictimes.indiatimes.com/news/cert-in-warns-of-multiple-vulnerabilities-in-iphones-ipads/95109515" target="_blank" rel="noreferrer noopener">Economic Times </a></em>report, iPhone and iPads have been facing vulnerabilities due to the new iOS and iPadOS updates. The information arrives from an advisory by the Indian Computer Emergency Response Team (Cert-IN). This report stated that the latest iOS and iPadOS builds feature a number of new vulnerabilities that would allow hackers with malicious intent to remotely access a user’s private data, run arbitrary code and spoof the interface address. Furthermore, these hackers could possibly even run denial of service programs remotely on the victim&#8217;s iPhone or iPad.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="576" src="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg?x23692" alt="Apple" class="wp-image-492605" srcset="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x.jpg 1312w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>As per Cert-IN, several iPhones from the Cupertino based giant are vulnerable to cyberattacks if they are running on iOS 16.1 and iOS 16.0.3 builds. Similarly, the security flaw also affects iPads running on iPadOS versions prior to the iPadOS 16.1 build. Due to this issue, the Apple iPhone 8 and after models are affected, while the iPad Pro Call models, iPad Air 3rd Gen and later, iPad 5th Gen and later, and even the iPad mini 5th gen and newer models are also among the list of affected devices.</p>



<p>Cert-IN stated that the severity of these vulnerabilities is high and is caused because of inadequate security controls in the AppleMobileFileIntegrity component among a number of other factors as well. Now, hackers could exploit these vulnerabilities by having the user open a malicious file or application. These files or apps would include harmful firmware that could help the hacker gain access to the victim&#8217;s device.</p>



<p><strong>RELATED:</strong></p>



<ul><li><a href="https://www.gizmochina.com/2022/10/26/iphone-15-usb-c-port-apple-complies-eu/">iPhone 15 to launch with USB-C port, as Apple complies with EU law: Report</a></li><li><a href="https://www.gizmochina.com/2022/10/25/apple-launch-macbook-pro-mac-mini-soon/">Apple may launch new MacBook Pro and Mac mini models in the coming months</a></li><li><a href="https://www.gizmochina.com/2022/10/25/apple-releases-ipados-16/">Apple releases iPadOS 16 with Stage Manager, Weather app, and more</a></li><li><a href="https://www.gizmochina.com/2022/10/24/apple-iphone-15-ultra-kill-base-iphone/">Apple iPhone 15 Ultra might kill off the 6.1 inch base iPhone model</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="uleFone Armor 17 Pro Review: MagSafe, with a rugged phone" width="696" height="392" src="https://www.youtube.com/embed/cyPtnCmxnn4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
</div></figure>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/10/27/apple-ipad-iphone-security-vulnerability/">Apple iPhone, iPads face new vulnerabilities in latest iOS &amp; iPadOS</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Zoom fixes security flaw that let hackers gain root access to your Mac</title>
		<link>https://www.gizmochina.com/2022/08/16/zoom-fixes-security-flaw-hackers-gain-root-access-mac/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Tue, 16 Aug 2022 10:28:01 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[zoom]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=475535</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-300x200.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Zoom Logo" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo.jpg 864w" sizes="(max-width: 300px) 100vw, 300px" /><p>Zoom has just rolled out a new update for its application on Apple Mac platform. The new update patches a major security vulnerability that would allow hackers to gain deep access to one&#8217;s Mac system. According to a ArsTechnica report, the popular cloud based video conferencing service had to patch a major security flaw that [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/08/16/zoom-fixes-security-flaw-hackers-gain-root-access-mac/">Zoom fixes security flaw that let hackers gain root access to your Mac</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-300x200.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Zoom Logo" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo.jpg 864w" sizes="(max-width: 300px) 100vw, 300px" /><p><a href="https://www.gizmochina.com/tag/zoom/" target="_blank" rel="noopener">Zoom</a> has just rolled out a new update for its application on Apple Mac platform. The new update patches a major security vulnerability that would allow hackers to gain deep access to one&#8217;s Mac system.</p>
<p><img loading="lazy" class="size-full wp-image-403394 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo.jpg?x23692" alt="Zoom Logo" width="864" height="576" srcset="https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo.jpg 864w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/08/Zoom-Logo-630x420.jpg 630w" sizes="(max-width: 864px) 100vw, 864px" /></p>
<p>According to a <a href="https://arstechnica.com/information-technology/2022/08/zoom-patches-mac-auto-updater-vulnerability-that-granted-root-access/?utm_brand=arstechnica&amp;utm_source=twitter&amp;utm_social-type=owned&amp;utm_medium=social" target="_blank" rel="noopener"><em>ArsTechnica</em> </a>report, the popular cloud based video conferencing service had to patch a major security flaw that enabled people with malicious to gain root level access to one&#8217;s Mac PCs. This would let the hackers take control of their systems. Apparently, this vulnerability stemmed from the Zoom application&#8217;s auto updater software, which had root level access to the system. This software only had a signature verification system that could be easily fooled by giving your package a familiar file name.</p>
<p>In other words, a hacker could potentially force your app to downgrade or otherwise enable exploits as well. The security flaw was first discovered by Patrick Wardle, the Objective-See Foundation (OSF) creator and researcher. Wardle had informed Zoom regarding this vulnerability back in December 2021. Now, the company has officially fixed this issue, although, the patch also brought another bug as well.</p>
<p>However, this was also soon fixed by Zoom, but Wardle found yet another bug in the application which was just recently patched as well. Notably, this isn&#8217;t the first time Zoom faced security related issues with its platform for the Mac systems. The company also had to quickly fix a webcam hijack exploit back in 2019, which lead to rise in criticism of the software, especially in 2020 when the app exploded in popularity.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/08/16/bgmi-will-likely-return-to-indian-market-very-soon/" target="_blank" rel="noopener">BGMI will likely return to Indian market very soon: Report</a></li>
<li><a href="https://www.gizmochina.com/2022/08/16/iqoo-z6-lite-launch-september-specs-price-range/" target="_blank" rel="noopener">iQOO Z6 Lite to launch in September, specs &amp; price range revealed</a></li>
<li><a href="https://www.gizmochina.com/2022/08/16/apple-iphone-14-pro-14-pro-max-hands-on-impression/" target="_blank" rel="noopener">Apple iPhone 14 Pro &amp; iPhone 14 Pro Max hands on impressions leaked, and it seems disappointing</a></li>
</ul>
<p><iframe loading="lazy" title="nubia Z40S Pro Full Review: A well-balanced phones with a periscopic telephoto lens" width="696" height="392" src="https://www.youtube.com/embed/JEyrrk8d_1k?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/08/16/zoom-fixes-security-flaw-hackers-gain-root-access-mac/">Zoom fixes security flaw that let hackers gain root access to your Mac</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google Pixel 6a fingerprint scanner suffers from a major security flaw</title>
		<link>https://www.gizmochina.com/2022/07/25/google-pixel-6a-fingerprint-scanner-security-flaw/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Mon, 25 Jul 2022 11:27:28 +0000</pubDate>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Pixel 6a]]></category>
		<category><![CDATA[security flaw]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=472288</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-300x200.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Pixel 6a under-display fingerprint scanner" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-1024x682.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner.jpg 1364w" sizes="(max-width: 300px) 100vw, 300px" /><p>Google is set to unveil its only Pixel 6 series smartphone in India later this month. However, prior to its July 28 release, the Pixel 6a model is apparently suffering from a major security flaw. The news arrives from known Indian tech YouTubers GeekyRanjit and Beebom who found the security issue in their videos. The [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/07/25/google-pixel-6a-fingerprint-scanner-security-flaw/">Google Pixel 6a fingerprint scanner suffers from a major security flaw</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-300x200.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Pixel 6a under-display fingerprint scanner" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-1024x682.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner.jpg 1364w" sizes="(max-width: 300px) 100vw, 300px" /><p>Google is set to unveil its only Pixel 6 series smartphone in India later this month. However, prior to its July 28 release, the Pixel 6a model is apparently suffering from a major security flaw.</p>
<p><iframe loading="lazy" title="Pixel 6a Fingerprint Scanner Can&#039;t be Trusted" width="696" height="392" src="https://www.youtube.com/embed/RqkydbXgbMA?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>The news arrives from known Indian tech YouTubers GeekyRanjit and Beebom who found the security issue in their videos. The security flaw was also confirmed separately by <a href="https://www.91mobiles.com/hub/google-pixel-6a-in-display-fingerprint-scanner-security-flaw/" target="_blank" rel="noopener"><em>91Mobiles</em></a> as well. As of right now, it is unclear whether the bug is related to the software or hardware. But, the Pixel 6a can basically be unlocked with fingerprints that are not even registered in the device. To put things simply, the in display fingerprint scanner is not functioning as intended, which shows a major security flaw.</p>
<p>In one of these videos, we can see multiple different people being capable of unlocking the Pixel 6a. So if your device gets lost or stolen, any other person can gain access to the smartphone. This is a big issue especially for the Search Engine giant, who is selling a smartphone after a gap of two years. Furthermore, the handset isn&#8217;t exactly affordable, with its price tag of 43,999 INR (roughly 550 US Dollars).</p>
<p><figure id="attachment_465120" aria-describedby="caption-attachment-465120" style="width: 1364px" class="wp-caption aligncenter"><img loading="lazy" class="wp-image-465120 size-full" src="https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner.jpg?x23692" alt="Google" width="1364" height="909" srcset="https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner.jpg 1364w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-1024x682.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/06/Pixel-6a-unboxing-fingerprint-scanner-630x420.jpg 630w" sizes="(max-width: 1364px) 100vw, 1364px" /><figcaption id="caption-attachment-465120" class="wp-caption-text">Pixel 6a in display fingerprint scanner</figcaption></figure></p>
<p>Talking about the smartphone itself, it sports a 6.1 inch Full HD+ OLED display that supports HDR. The Pixel 6a is also equipped with the company&#8217;s proprietary Tensor chipset that is paired with 6GB of RAM and 128GB of internal storage. It is powered by a 4,306mAh battery pack that also supports 18W fast charging. For photography, the device features a 12.2 megapixel dual camera setup on the rear and an 8 megapixel selfie shooter.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/07/25/google-fires-software-engineer-claiming-chatbot-sentient/" target="_blank" rel="noopener">Google fires software engineer that claimed that its AI chatbot is self aware</a></li>
<li><a href="https://www.gizmochina.com/2022/07/21/google-pixel-buds-pro-launched-in-india-all-details/" target="_blank" rel="noopener">Google Pixel Buds Pro Launched in India with ANC, Up to 31 Hours Battery: All Details</a></li>
<li><a href="https://www.gizmochina.com/2022/07/21/hisense-a6h-series-4k-google-tv-launch-india-price-of-rs-29990/" target="_blank" rel="noopener">Hisense A6H Series 4K Google TV to launch in India at starting price of Rs 29,990</a></li>
</ul>
<p><iframe loading="lazy" title="HAYLOU PurFree BC01 Review: Feeling music with bones." width="696" height="392" src="https://www.youtube.com/embed/NoVNHsyd6d4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/07/25/google-pixel-6a-fingerprint-scanner-security-flaw/">Google Pixel 6a fingerprint scanner suffers from a major security flaw</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Smartphones with Unisoc SoCs have a critical vulnerability, fix in works</title>
		<link>https://www.gizmochina.com/2022/06/02/smartphones-with-unisoc-socs-have-a-critical-vulnerability/</link>
		
		<dc:creator><![CDATA[Sudhanshu]]></dc:creator>
		<pubDate>Thu, 02 Jun 2022 18:50:48 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[UNISOC]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Unisoc]]></category>
		<category><![CDATA[UNISOC chip security flaw]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=463749</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-300x200.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="UNISOC T7520 6nm 5G Chipset Featured" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>China-based semiconductor firm Unisoc has recently come to prominence with multiple major manufacturers using its SoCs in their budget range devices. Now, Check Point Research has revealed that the Unisoc smartphone chips have a critical security vulnerability. According to the firm, The issue exists in the modem firmware and affects 4G and 5G Unisoc chipsets. [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/06/02/smartphones-with-unisoc-socs-have-a-critical-vulnerability/">Smartphones with Unisoc SoCs have a critical vulnerability, fix in works</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-300x200.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="UNISOC T7520 6nm 5G Chipset Featured" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>China-based semiconductor firm <a href="https://www.gizmochina.com/tag/Unisoc/" target="_blank" rel="noopener">Unisoc</a> has recently come to prominence with multiple major manufacturers using its SoCs in their budget range devices. Now, <a href="https://blog.checkpoint.com/2022/06/02/check-point-research-unveils-vulnerability-within-unisoc-baseband-chipset/" target="_blank" rel="noopener"><em>Check Point Research</em></a> has revealed that the Unisoc smartphone chips have a critical security vulnerability.</p>
<p><img loading="lazy" class="aligncenter wp-image-353622 size-full" src="https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured.jpg?x23692" alt="UNISOC T7520 6nm 5G Chipset Featured" width="1920" height="1280" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/UNISOC-T7520-6nm-5G-Chipset-Featured-630x420.jpg 630w" sizes="(max-width: 1920px) 100vw, 1920px" /></p>
<p>According to the firm, The issue exists in the modem firmware and affects 4G and 5G Unisoc chipsets. The issue, tracked as CVE-2022-20210, was discovered while scanning Non-Access Stratum (NAS) message handlers. This vulnerability could be exploited to neutralize or block the cellular communication capabilities of the device.</p>
<p>Slava Makkaveev,  Reverse Engineering and Security Research attorney at Check Point Software said &#8220;An attacker could have used a radio station to send a malformed packet that would reset the modem, depriving the user of the possibility of communication. Left unpatched, cellular communication can be blocked by an attacker.&#8221;</p>
<p>The vulnerability was detected on a <a href="https://www.gizmochina.com/product/motorola-moto-g20/" target="_blank" rel="noopener">Motorola Moto G20</a> running the <a href="https://www.gizmochina.com/tag/Unisoc-T700/" target="_blank" rel="noopener">Unisoc T700</a> chipset and Android January 2022 security patch. The vulnerability, however, exists on other devices using Unisoc chipsets too. Check Point Research disclosed its findings to Unisoc in May. The China-based chipmaker acknowledged the vulnerability upon the receipt of disclosure and issued a patch.</p>
<p>Makkaveev also stated that &#8220;There is nothing for Android users to do right now, though we strongly recommend applying a patch that will be released by Google in their upcoming Android Security Bulletin.&#8221; So, it is advisable to update your Unisoc SoC smartphones to the latest software version when the next patch arrives.</p>
<p>&nbsp;</p>
<p><span style="text-decoration: underline"><strong>RELATED:</strong></span></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/05/04/moto-e32-launched-with-90hz-display-unisoc-t606-5000mah-battery/" target="_blank" rel="noopener">Moto E32 launched with 90Hz display, Unisoc T606, 5,000mAh battery</a></li>
<li><a href="https://www.gizmochina.com/2022/04/26/nokia-g21-india-launch-price/" target="_blank" rel="noopener">Nokia G21 launched in India with 90Hz display, Unisoc T606 chip, and more</a></li>
<li><a href="https://www.gizmochina.com/2022/05/31/zte-blade-v40-vita-unisocs-t606-soc-launched-malaysia/" target="_blank" rel="noopener">ZTE Blade V40 Vita with Unisoc’s T606 SoC launched in Malaysia</a></li>
</ul>
<p><iframe loading="lazy" title="Xiaomi Mi Band 7 NFC Smart wearable Review: Still one of the best entry-level wearables" width="696" height="392" src="https://www.youtube.com/embed/jH08rUz-Bq8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/06/02/smartphones-with-unisoc-socs-have-a-critical-vulnerability/">Smartphones with Unisoc SoCs have a critical vulnerability, fix in works</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPad Pro with M1 chips have an irreparable security flaw</title>
		<link>https://www.gizmochina.com/2021/05/27/apple-m1-ipad-pro-irreparable-security-flaw/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 27 May 2021 08:54:48 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iPad Pro]]></category>
		<category><![CDATA[M1 chip]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=391725</guid>

					<description><![CDATA[<img width="300" height="168" src="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Apple M1 Chip" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-768x429.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1024x573.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-696x389.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1068x597.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-751x420.jpg 751w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1920x1074.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>The propriety M1 Chip from Apple has already made its way to a number of the company&#8217;s products. This includes MacBooks, iMacs, iMac mini, and even the iPad Pro. Now, a new report has found that the iPad Pro with the company&#8217;s silicon has an irreparable security flaw. According to developer Hector Martin (Via PhoneArena), [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/05/27/apple-m1-ipad-pro-irreparable-security-flaw/">Apple iPad Pro with M1 chips have an irreparable security flaw</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="168" src="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="Apple M1 Chip" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-768x429.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1024x573.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-696x389.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1068x597.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-751x420.jpg 751w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1920x1074.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>The propriety <a href="https://www.gizmochina.com/tag/apple-m1/" target="_blank" rel="noopener noreferrer">M1 Chip</a> from <a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noopener noreferrer">Apple</a> has already made its way to a number of the company&#8217;s products. This includes MacBooks, iMacs, iMac mini, and even the iPad Pro. Now, a new report has found that the iPad Pro with the company&#8217;s silicon has an irreparable security flaw.</p>
<p><img loading="lazy" class="aligncenter wp-image-353316 size-full" src="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png?x23692" alt="Apple m1 chip" width="715" height="402" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png 715w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-696x391.png 696w" sizes="(max-width: 715px) 100vw, 715px" /></p>
<p>According to developer <a href="https://m1racles.com/" target="_blank" rel="nofollow noopener noreferrer">Hector Martin</a> (Via <a href="https://www.phonearena.com/news/apple-m1-security-vulnerability_id132376" target="_blank" rel="noopener noreferrer">PhoneArena</a>), the M1 based iPad Pro suffers from a vulnerability that exists on a hardware level of the M1. In other words, this is an issue that cannot be fixed through a simple software update. The Cupertino based giant has apparently violated an Arm architecture specification requirement as well. This means that there is no simple method of fixing the issue.</p>
<p>The developer further explained that the flaw basically allows two applications to covertly exchange data without using normal operating system features. While this is a vulnerability, it, fortunately, does not pose any serious security risks. Even in a worst case scenario this security risk would only enable advertisers for cross app tracking and can not be used by hackers to take control of one&#8217;s device or even steal sensitive information. Although, the flaw still violates the OS security model.</p>
<p><img loading="lazy" class="aligncenter wp-image-385382 size-full" src="https://www.gizmochina.com/wp-content/uploads/2021/04/image.png?x23692" alt="Apple iPad Pro" width="817" height="435" srcset="https://www.gizmochina.com/wp-content/uploads/2021/04/image.png 817w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-300x160.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-768x409.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-696x371.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-789x420.png 789w" sizes="(max-width: 817px) 100vw, 817px" /></p>
<p>Furthermore, this issue affects every M1 device, which means it could even affect the <a href="https://www.gizmochina.com/tag/iphone-12/" target="_blank" rel="noopener noreferrer">iPhone 12</a> series as well since the <a href="https://www.gizmochina.com/tag/apple-a14/" target="_blank" rel="noopener noreferrer">A14 Bionic</a> is based on the same CPU microarchitecture. The developer said that the only way of fixing this is to run the entire operating system as a virtual machine (VM). But that is not exactly a feasible repair to the issue. Hector believes that the flaw could even affect the next generation <a href="https://www.gizmochina.com/tag/m1x-chip/" target="_blank" rel="noopener noreferrer">M1X chipset</a> as well, but will be fixed in the following generation in the future.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2021/05/26/xiaomi-overtake-apple-q2-emerge-worlds-no-1-phone-maker/" target="_blank" rel="noopener noreferrer">Xiaomi hopes to overtake Apple in Q2 &amp;amp; to emerge world&#8217;s no. 1 phone maker in 3-5 years&#8217; time</a></li>
<li><a href="https://www.gizmochina.com/2021/05/26/apple-m1x-mac-mini-thinner-chassis-magnetic-connector/" target="_blank" rel="noopener noreferrer">Apple M1X Mac mini to feature thinner chassis and new iMac&#8217;s magnetic power connector: Report</a></li>
<li><a href="https://www.gizmochina.com/2021/05/26/apple-patent-iphone-display-glass-thinner-stronger/" target="_blank" rel="noopener noreferrer">Apple working on a way to make iPhone display glass thinner and stronger: Patent</a></li>
</ul>
<p><iframe loading="lazy" title="Xiaomi Flipbuds Pro Full Review: The strongest Xiaomi earbuds so far" width="696" height="392" src="https://www.youtube.com/embed/9-Z-09P0iR4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/05/27/apple-m1-ipad-pro-irreparable-security-flaw/">Apple iPad Pro with M1 chips have an irreparable security flaw</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Huawei forced to fix critical flaws in its equipment by British Intelligence</title>
		<link>https://www.gizmochina.com/2020/10/02/huawei-fix-flaw-in-equipment-by-british-intelligence/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Fri, 02 Oct 2020 07:43:31 +0000</pubDate>
				<category><![CDATA[Huawei]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Britain]]></category>
		<category><![CDATA[Huawei UK]]></category>
		<category><![CDATA[security flaw]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=345845</guid>

					<description><![CDATA[<img width="300" height="185" src="https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-300x185.png?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="huawei" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-300x185.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-768x474.png 768w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-356x220.png 356w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-696x430.png 696w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-680x420.png 680w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g.png 834w" sizes="(max-width: 300px) 100vw, 300px" /><p>Huawei Technologies has recently been forced to fix a major flaw in its products by the British Intelligence, which put the security of the country&#8217;s networks at risk, as per a government agency. The UK government found a &#8220;Critical, user-facing vulnerabilities” in the system regarding the Chinese telecommunications giant&#8217;s fixed-broadband products. The issue was caused [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/10/02/huawei-fix-flaw-in-equipment-by-british-intelligence/">Huawei forced to fix critical flaws in its equipment by British Intelligence</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="185" src="https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-300x185.png?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="huawei" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-300x185.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-768x474.png 768w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-356x220.png 356w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-696x430.png 696w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-680x420.png 680w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g.png 834w" sizes="(max-width: 300px) 100vw, 300px" /><p><a href="https://www.gizmochina.com/tag/huawei/" target="_blank" rel="noopener noreferrer">Huawei Technologies</a> has recently been forced to fix a major flaw in its products by the British Intelligence, which put the security of the country&#8217;s networks at risk, as per a government agency.</p>
<p><img loading="lazy" class="aligncenter wp-image-332810 size-full" src="https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g.png?x23692" alt="huawei" width="834" height="515" srcset="https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g.png 834w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-300x185.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-768x474.png 768w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-356x220.png 356w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-696x430.png 696w, https://www.gizmochina.com/wp-content/uploads/2020/07/huawei-5g-680x420.png 680w" sizes="(max-width: 834px) 100vw, 834px" /></p>
<p>The UK government found a &#8220;Critical, user-facing vulnerabilities” in the system regarding the Chinese telecommunications giant&#8217;s fixed-broadband products. The issue was caused by poor code quality and an old operating system, according to Huawei Cyber Security Evaluation Centre Oversight Board. This center was built by the company alongside the government in an arrangement to let the British National Cyber Security Centre examine its hardware and software.</p>
<h6 class="related"><strong>Editor&#8217;s Pick: <a href="https://www.gizmochina.com/2020/10/02/apple-iphone-12-models-variant-leak/" target="_blank" rel="noopener noreferrer">Entry-level Apple iPhone 12 models pack 64GB storage while Pro models start at 128GB storage</a></strong></h6>
<p>Since then, an annual report from HCSEC Oversight Board has stated that the security issue has been cleared and as such, no exploitations were detected. However, the fix also created a new and &#8220;major issue,” which is said to be caused by the &#8220;deficiencies in Huawei’s engineering processes remain.&#8221; The report from <a href="https://www.scmp.com/news/world/europe/article/3103889/britain-found-critical-weakness-huawei-equipment" target="_blank" rel="noopener noreferrer"><em>SCMP</em> </a>mentioned the event had &#8220;national significance,&#8221; and being a rare occasion where a full description of the problem was temporarily withheld from Huawei as the impact was assessed.</p>
<p><img loading="lazy" class="aligncenter wp-image-324411 size-full" src="https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019.jpg?x23692" alt="Huawei Logo MWC 2019" width="3000" height="2000" srcset="https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019.jpg 3000w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2020/05/Huawei-Logo-MWC-2019-1920x1280.jpg 1920w" sizes="(max-width: 3000px) 100vw, 3000px" /></p>
<p>Notably, the discovery of the critical flaw arrived during the time when the British government had decided to <a href="https://www.gizmochina.com/2020/07/14/huawei-technology-banned-from-uks-5g-networks/" target="_blank" rel="noopener noreferrer">ban the Chinese company from supplying the nation with equipment for 5G networking</a>. The government is also currently reviewing its role in supplying fixed-broadband infrastructure. The HCSEC Oversight Board stated that it &#8220;can only provide limited technical assurance in the security risk management of Huawei equipment in UK networks.&#8221;</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/10/01/whatsapp-beta-for-android-v2-20-201-10-adds-always-mute-new-storage-usage-ui-media-guidelines/" target="_blank" rel="noopener noreferrer">WhatsApp Beta for Android v2.20.201.10 adds Always Mute, new Storage Usage UI &amp; Media Guidelines</a></strong></h6>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/10/02/huawei-fix-flaw-in-equipment-by-british-intelligence/">Huawei forced to fix critical flaws in its equipment by British Intelligence</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Microsoft rolls out emergency updates to fix Security flaws on Windows 10</title>
		<link>https://www.gizmochina.com/2020/07/01/microsoft-rolls-out-emergency-updates-to-fix-security-flaws-on-windows-10/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Wed, 01 Jul 2020 09:55:58 +0000</pubDate>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Windows 10]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=329955</guid>

					<description><![CDATA[<img width="300" height="134" src="https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-300x134.png?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="microsoft logo" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-300x134.png 300w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-768x344.png 768w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-1024x459.png 1024w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht.png 2008w" sizes="(max-width: 300px) 100vw, 300px" /><p>Microsoft has recently rolled out two emergency updates that fix certain security flaws in its Windows 10 and Windows Server operating systems. This update arrives just two weeks earlier than its regular Tuesday Patch cycle. According to Microsoft, the flaws had not been publicly revealed so its chances of exploitation were low, but regardless, the [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/07/01/microsoft-rolls-out-emergency-updates-to-fix-security-flaws-on-windows-10/">Microsoft rolls out emergency updates to fix Security flaws on Windows 10</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="134" src="https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-300x134.png?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="microsoft logo" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-300x134.png 300w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-768x344.png 768w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-1024x459.png 1024w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht.png 2008w" sizes="(max-width: 300px) 100vw, 300px" /><p><a href="https://www.gizmochina.com/tag/microsoft/" target="_blank" rel="noopener noreferrer">Microsoft</a> has recently rolled out two emergency updates that fix certain security flaws in its <a href="https://www.gizmochina.com/tag/windows-10/" target="_blank" rel="noopener noreferrer">Windows 10</a> and Windows Server operating systems. This update arrives just two weeks earlier than its regular Tuesday Patch cycle.</p>
<p><img loading="lazy" class="aligncenter wp-image-214162 size-full" src="https://www.gizmochina.com/wp-content/uploads/2018/09/Microsoft-Surface-Pro-6-Leaks-3.jpg?x23692" alt="Microsoft Surface Pro 6 Leaks" width="1280" height="854" srcset="https://www.gizmochina.com/wp-content/uploads/2018/09/Microsoft-Surface-Pro-6-Leaks-3.jpg 1280w, https://www.gizmochina.com/wp-content/uploads/2018/09/Microsoft-Surface-Pro-6-Leaks-3-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/09/Microsoft-Surface-Pro-6-Leaks-3-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2018/09/Microsoft-Surface-Pro-6-Leaks-3-1024x683.jpg 1024w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>
<p>According to Microsoft, the flaws had not been publicly revealed so its chances of exploitation were low, but regardless, the company hurried to patch the vulnerabilities that affected both platforms rather than waiting for the July 14 update cycle. The security flaws in question have been labeled as CVE-2020-1425 and CVE-2020-1457, which allow exploiters to execute arbitrary code and take control of the affected computer.</p>
<h6 class="related"><strong>Editor&#8217;s Pick: <a href="https://www.gizmochina.com/2020/07/01/apple-tests-macos-on-iphone/">Apple tests macOS on an iPhone, enables desktop experience through Docking: Report</a></strong></h6>
<p>Apparently, these flaws existed due to the way Windows Codecs Library handles objects in memory. In other words, a potential attacker could hack into a system by using a crafted image file that would need to launch on the targeted computer. The company also revealed the list of the versions of operating systems that suffered from this issue, which includes:</p>
<ul>
<li>Windows 10 version 1709</li>
<li>Windows 10 version 1803</li>
<li>Windows 10 version 1809</li>
<li>Windows 10 version 1903</li>
<li>Windows 10 version 1909</li>
<li>Windows 10 version 2004</li>
<li>Windows Server 2019</li>
<li>Windows Server version 1803</li>
<li>Windows Server version 1903</li>
<li>Windows Server version 1909</li>
<li>Windows Server version 2004</li>
</ul>
<p><img loading="lazy" class="aligncenter wp-image-219771 size-full" src="https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht.png?x23692" alt="microsoft logo" width="2008" height="900" srcset="https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht.png 2008w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-300x134.png 300w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-768x344.png 768w, https://www.gizmochina.com/wp-content/uploads/2018/10/Microsoft-logo_rgb_wht-1024x459.png 1024w" sizes="(max-width: 2008px) 100vw, 2008px" /></p>
<p>The security flaws were first reported to the company by Trend Micro Zero Day Initiative security researcher Abdul-Aziz Hariri. Users can now download the update from the Microsoft Store in the forms of patches that will update the Windows Media Codec. Although, these updates have been sent out automatically as well.</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/07/01/honor-30-youth-edition-to-feature-ai-speed-capture-enables-detailed-movement-shots/">Honor 30 Youth Edition to feature AI Speed Capture, enables detailed movement shots</a></strong></h6>
<p>&nbsp;</p>
<p>(<a href="https://news.softpedia.com/news/microsoft-releases-emergency-windows-10-updates-to-resolve-security-flaws-530412.shtml" target="_blank" rel="noopener noreferrer">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/07/01/microsoft-rolls-out-emergency-updates-to-fix-security-flaws-on-windows-10/">Microsoft rolls out emergency updates to fix Security flaws on Windows 10</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPhone&#8217;s Mail App suffers from a severe security flaw, Company declined to comment</title>
		<link>https://www.gizmochina.com/2020/04/23/apple-iphones-mail-app-suffers-from-a-severe-security-flaw-company-declined-to-comment/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 23 Apr 2020 09:58:00 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=318751</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr.jpg 640w" sizes="(max-width: 300px) 100vw, 300px" /><p>A new vulnerability might have just been found in Apple iPhones. Security researchers have claimed that the default iOS Mail app suffers from a severe security flaw and is vulnerable to attacks from hackers. According to a report from ZecOps, the vulnerability is already being exploited &#8220;in the wild&#8221; and that it is an advanced [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/04/23/apple-iphones-mail-app-suffers-from-a-severe-security-flaw-company-declined-to-comment/">Apple iPhone&#8217;s Mail App suffers from a severe security flaw, Company declined to comment</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr.jpg 640w" sizes="(max-width: 300px) 100vw, 300px" /><p>A new vulnerability might have just been found in <a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noopener noreferrer">Apple</a> iPhones. Security researchers have claimed that the default iOS Mail app suffers from a severe security flaw and is vulnerable to attacks from hackers.</p>
<p>According to a report from ZecOps, the vulnerability is already being exploited &#8220;in the wild&#8221; and that it is an advanced threat that Apple is unaware of. The research agency believes that at least 6 high profile targets have been exploited so far, including a Japanese mobile carrier executive and other &#8220;individuals from a Fortune 500 company in North America.”</p>
<p><img loading="lazy" class="aligncenter wp-image-116923 size-full" src="https://www.gizmochina.com/wp-content/uploads/2017/02/apple-iphones.jpg?x23692" alt="apple india" width="1200" height="900" /></p>
<p>ZecOps have refrained from mentioning names stating privacy reasons but said that it was unable to obtain the malicious code since the emails were remotely deleted by hackers. The firm believes that the vulnerability is related to 2 zero-day iOS exploits that have existed in the Mail app since at least iOS 6, which was launched back in 2012.</p>
<h6 class="related"><strong>Editor&#8217;s Pick: <a href="https://www.gizmochina.com/2020/04/23/realme-x50m-5g-launched-with-120hz-display-sd765g-30w-charging-and-48mp-quad-cameras-for-1999-yuan-282/">Realme X50m 5G launched with 120Hz display, SD765G, 30W charging and 48MP quad cameras for 1,999 Yuan (~$282)</a></strong></h6>
<p>According to ZecOps, &#8220;the attack’s scope consists of sending a specially crafted email to a victim’s mailbox enabling it to trigger the vulnerability in the context of iOS MobileMail application on iOS 12 or mailed on iOS 13.” However, the method to reproduce this vulnerability has failed so far by various other researchers. This includes Jann Horn and Maddie Stone from Google&#8217;s Project Zero cybersecurity program.</p>
<blockquote class="twitter-tweet" data-width="550" data-dnt="true">
<p lang="en" dir="ltr"><a href="https://twitter.com/ZecOps?ref_src=twsrc%5Etfw">@ZecOps</a> your writeup says &quot;The suspicious events included strings commonly used by hackers (e.g. 414141…4141).&quot;, but that&#39;s also what it looks like when you just base64-encode nullbytes; and this is MIME parsing, so you&#39;re likely to see base64-encoded data</p>
<p>&mdash; Jann Horn (@tehjh) <a href="https://twitter.com/tehjh/status/1253010131283034114?ref_src=twsrc%5Etfw">April 22, 2020</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p>Notably, Apple was reached out from Beijing News reported in China to verify the report from ZecOps, regarding the vulnerability the iOS mail app faces on iPhones. Unfortunately, Apple China declined to comment on the situation so we have no official confirmation. Other researchers are currently asking ZecOps to provide more details on how to recreate the vulnerability to actually prove the security flaw&#8217;s existence.</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/04/23/huawei-to-soon-launch-headphones-and-smart-eyewear-powered-by-the-kirin-a1-chip-report/">Huawei to soon launch headphones and smart eyewear powered by the Kirin A1 chip: Report</a></strong></h6>
<p>&nbsp;</p>
<p>(Via:<a href="https://www.theverge.com/2020/4/22/21231454/apple-iphone-zero-day-exploit-security-flaw-mail-app-ios-zec-ops" target="_blank" rel="noopener noreferrer">1</a>,<a href="https://tech.sina.com.cn/it/2020-04-23/doc-iircuyvh9404703.shtml?cre=tianyi&amp;mod=pctech&amp;loc=2&amp;r=25&amp;rfunc=96&amp;tj=none&amp;tr=25" target="_blank" rel="noopener noreferrer">2</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/04/23/apple-iphones-mail-app-suffers-from-a-severe-security-flaw-company-declined-to-comment/">Apple iPhone&#8217;s Mail App suffers from a severe security flaw, Company declined to comment</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>OnePlus 6 Serious Flaw Makes It Easy For Anyone To Take Control Of The Device</title>
		<link>https://www.gizmochina.com/2018/06/10/oneplus-6-serious-flaw-makes-easy-for-everyone-to-take-control-of-the-device/</link>
		
		<dc:creator><![CDATA[Michele Ingelido]]></dc:creator>
		<pubDate>Sun, 10 Jun 2018 18:41:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Oneplus]]></category>
		<category><![CDATA[OnePlus]]></category>
		<category><![CDATA[OnePlus 6]]></category>
		<category><![CDATA[oneplus 6 flaw]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[XDA Developers]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=195616</guid>

					<description><![CDATA[<img width="300" height="231" src="https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-300x231.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-300x231.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-768x592.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-285x220.jpg 285w, https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3.jpg 800w" sizes="(max-width: 300px) 100vw, 300px" /><p>Security on Android phones is never an assurance, but this time the red line zone has been passed. A new flaw has been discovered on the OnePlus 6: it can enable anyone to take total control of the device easily. The flaw is with regards to the bootloader and in order to take advantage of [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2018/06/10/oneplus-6-serious-flaw-makes-easy-for-everyone-to-take-control-of-the-device/">OnePlus 6 Serious Flaw Makes It Easy For Anyone To Take Control Of The Device</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="231" src="https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-300x231.jpg?x23692" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-300x231.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-768x592.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3-285x220.jpg 285w, https://www.gizmochina.com/wp-content/uploads/2018/05/OnePlus-6_3.jpg 800w" sizes="(max-width: 300px) 100vw, 300px" /><p>Security on Android phones is never an assurance, but this time the red line zone has been passed. A new flaw has been discovered on the <a href="http://gizmochina.com/product/oneplus-6">OnePlus 6</a>: it can enable anyone to take total control of the device easily. The flaw is with regards to the bootloader and in order to take advantage of this flaw, you just need the physical access to the device and a PC. It has been discovered by Jason Donenfeld, an XDA member and president of Edge Security LLC. If you have some basic idea of Android modding, then you might know that the standard bootloader installed on smartphones prevents installing custom ROMs on the device.</p>
<p><img loading="lazy" class="aligncenter size-full wp-image-192410" src="https://www.gizmochina.com/wp-content/uploads/2018/05/oneplus-6-no-wireless-charge.jpg?x23692" alt="OnePlus 6" width="1509" height="754" srcset="https://www.gizmochina.com/wp-content/uploads/2018/05/oneplus-6-no-wireless-charge.jpg 1509w, https://www.gizmochina.com/wp-content/uploads/2018/05/oneplus-6-no-wireless-charge-300x150.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/05/oneplus-6-no-wireless-charge-768x384.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2018/05/oneplus-6-no-wireless-charge-1024x512.jpg 1024w" sizes="(max-width: 1509px) 100vw, 1509px" /></p>
<p>But due to the big flaw, the bootloader of the OnePlus 6 allows installing every customized system image, even though the bootloader is locked. To do so, the user needs physical access to the device and it has to be connected to the PC at least once. Then, you just need to boot the phone through the fastboot mode and flash the customized image. You can even install custom recoveries such as TWRP and obtain root access, and if you do so, there will be no usage limits.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>RELATED: <a href="https://www.gizmochina.com/2018/05/30/oneplus-6-face-unlock-feature-bypassed-using-a-printed-photo/">OnePlus 6 Face Unlock Feature Bypassed Using A Printed Photo</a></strong></p>
<p>&nbsp;</p>
<p>So, if you own a unit of the OnePlus 6 and you actually lose your device or someone steals it, he can easily take total control of it and delete all of your data. After the discovery, OnePlus has been alerted and it has already released a statement on the matter. Here are the words spoken by the company:</p>
<blockquote><p>We take security seriously at OnePlus. We are in contact with the security researcher, and a software update will be rolling out shortly.</p></blockquote>
<p>A software update for the OnePlus 6 to fix the big flaw should arrive soon, but in the meantime make sure not to lose your device!</p>
<p>(<a href="https://www.xda-developers.com/oneplus-6-bootloader-protection-exploit-physical-access/">Source</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2018/06/10/oneplus-6-serious-flaw-makes-easy-for-everyone-to-take-control-of-the-device/">OnePlus 6 Serious Flaw Makes It Easy For Anyone To Take Control Of The Device</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 131/224 objects using Redis
Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudflare
Database Caching 8/41 queries in 0.018 seconds using Redis
Fragment Caching 2/3 fragments using Redis

Served from: www.gizmochina.com @ 2026-08-15 10:14:04 by W3 Total Cache
-->