<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vulnerability Archives - Gizmochina</title>
	<atom:link href="https://www.gizmochina.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.gizmochina.com/tag/vulnerability/</link>
	<description>Latest Tech News, Product Reviews and Deals</description>
	<lastBuildDate>Mon, 25 Sep 2023 07:24:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.9</generator>
	<item>
		<title>Potential threats for Apple users? Indian Govt issues high severity warning</title>
		<link>https://www.gizmochina.com/2023/09/25/threats-apple-users-indian-govt-issues-high-severity-warning/</link>
		
		<dc:creator><![CDATA[Soumyakanti]]></dc:creator>
		<pubDate>Mon, 25 Sep 2023 07:24:16 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Government of India]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=569572</guid>

					<description><![CDATA[<img width="300" height="180" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-300x180.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Tim-Cook" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-300x180.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1024x615.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-768x461.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1536x923.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-696x418.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1068x641.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-699x420.jpg 699w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook.jpg 1908w" sizes="(max-width: 300px) 100vw, 300px" /><p>CERT-In issued a high-severity warning regarding serious vulnerabilities found in multiple Apple products, such as iPhones and Apple Watches. These vulnerabilities could potentially allow hackers to execute arbitrary code, gain escalated privileges, or bypass security measures on the impacted devices. Understanding the Risks The vulnerabilities come from problems in certificate validation within key components like [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/09/25/threats-apple-users-indian-govt-issues-high-severity-warning/">Potential threats for Apple users? Indian Govt issues high severity warning</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="180" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-300x180.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Tim-Cook" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-300x180.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1024x615.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-768x461.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1536x923.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-696x418.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1068x641.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-699x420.jpg 699w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook.jpg 1908w" sizes="(max-width: 300px) 100vw, 300px" />
<p>CERT-In issued a high-severity warning regarding serious vulnerabilities found in multiple <a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noreferrer noopener">Apple</a> products, such as <a href="https://www.gizmochina.com/tag/iphone/" target="_blank" rel="noreferrer noopener">iPhones</a> and Apple Watches. These vulnerabilities could potentially allow hackers to execute arbitrary code, gain escalated privileges, or bypass security measures on the impacted devices.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="615" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1024x615.jpg?x44794" alt="" class="wp-image-569574" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1024x615.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-300x180.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-768x461.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1536x923.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-696x418.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-1068x641.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook-699x420.jpg 699w, https://www.gizmochina.com/wp-content/uploads/2023/09/Tim-Cook.jpg 1908w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption>Credit: AFP via Getty Images</figcaption></figure></div>



<h2>Understanding the Risks</h2>



<p>The vulnerabilities come from problems in certificate validation within key components like Security, Kernel, and WebKit in Apple products. Specifically, the flaws impact the Safari browser and other browsers using WebKit. These vulnerabilities enable attackers to bypass security protocols, gain elevated access rights, and execute arbitrary code on targeted systems.</p>



<p>The WebKit vulnerability poses a significant risk as it could enable attackers to take control of Apple devices, potentially accessing personal data, files, and even installing malware. This threat arises when users are lured to malicious websites or open harmful attachments. The security concerns extend to various Apple software versions, including <a href="https://www.gizmochina.com/tag/macos-monterey/" target="_blank" rel="noreferrer noopener">macOS Monterey</a>, <a href="https://www.gizmochina.com/tag/macos-ventura/" target="_blank" rel="noreferrer noopener">macOS Ventura</a>, <a href="https://www.gizmochina.com/tag/watchos/" target="_blank" rel="noreferrer noopener">watchOS</a>, <a href="https://www.gizmochina.com/tag/ios/" target="_blank" rel="noreferrer noopener">iOS</a>, <a href="https://www.gizmochina.com/tag/ipados/" target="_blank" rel="noreferrer noopener">iPadOS</a>, and <a href="https://www.gizmochina.com/tag/safari/" target="_blank" rel="noreferrer noopener">Safari</a>.</p>



<p>To reduce the risks associated with these vulnerabilities, users are strongly advised by the national authority to promptly update their Apple devices to the latest available versions. <a href="https://www.gizmochina.com/category/apple/" target="_blank" rel="noreferrer noopener">Apple</a> has released updates to address these vulnerabilities, which can be obtained from the official website, cert-in.org.in.</p>



<p>CERT-In is a central organization operating under the Ministry of Electronics and Information Technology, <a href="https://www.gizmochina.com/tag/government-of-india/" target="_blank" rel="noreferrer noopener">Government of India</a>.</p>



<p>Here’s the list of the affected software:</p>



<ul><li>Apple macOS Monterey versions prior to 12.7</li><li>Apple macOS Ventura versions prior to 13.6</li><li>Apple watchOS versions prior to 9.6.3</li><li>Apple watchOS versions prior to 10.0.1</li><li>Apple iOS versions prior to 16.7 and iPadOS versions prior to 16.7</li><li>Apple iOS versions prior to 17.0.1 and iPadOS versions prior to 17.0.1</li><li>Apple Safari versions prior to 16.6.1</li></ul>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/09/24/iphone-15-pro-overheating-due-to-a17-pro-chip/">iPhone 15 Pro Max reportedly experiencing severe overheating issues</a></li><li><a href="https://www.gizmochina.com/2023/09/24/apple-stores-warn-against-android-cables-potential-overheating/">Apple Stores warn against using Android cables due to potential overheating</a></li><li><a href="https://www.gizmochina.com/2023/09/23/iphone-15-pro-max-drives-apples-fourth-quarter-growth/">iPhone 15 Pro Max to drive Apple’s growth in Q4, analyst Ming-Chi Kuo says</a></li><li><a href="https://www.gizmochina.com/guides/download-best-gcam-for-redmi-12-5g/">Download the Best GCam APK for Redmi 12 5G</a></li><li><a href="https://www.gizmochina.com/guides/redmi-note-13-pro-vs-redmi-note-12-pro-specs-comparison/">Redmi Note 13 Pro vs Redmi Note 12 Pro: Specs Comparison</a></li><li><a href="https://www.gizmochina.com/guides/iphone-15-pro-max-vs-honor-magic5-ultimate-specs-comparison/">iPhone 15 Pro Max vs Honor Magic5 Ultimate: Specs Comparison</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Redmi Note 13 Pro Plus Unboxing &amp; Hands on: Redmi&#039;s most beautiful Note series phone is here." width="696" height="392" src="https://www.youtube.com/embed/aATp6f6ElSc?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://cert-in.org.in/" target="_blank" rel="noreferrer noopener">Source</a>, <a href="https://www.hindustantimes.com/technology/centre-issues-high-severity-warning-to-apple-users-check-details-101695535143501.html" target="_blank" rel="noreferrer noopener">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/09/25/threats-apple-users-indian-govt-issues-high-severity-warning/">Potential threats for Apple users? Indian Govt issues high severity warning</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Microsoft, Google, and Apple among most exploited in 2022 zero-day vulnerabilities</title>
		<link>https://www.gizmochina.com/2023/03/22/microsoft-google-apple-zero-day-vulnerabilities/</link>
		
		<dc:creator><![CDATA[Soumyakanti]]></dc:creator>
		<pubDate>Wed, 22 Mar 2023 07:55:33 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Security Patch]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=524345</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-300x200.webp?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="security-protection" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-300x200.webp 300w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1024x683.webp 1024w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-768x512.webp 768w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-696x464.webp 696w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1068x712.webp 1068w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-630x420.webp 630w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection.webp 1125w" sizes="(max-width: 300px) 100vw, 300px" /><p>According to a recent report by Mandiant, a leading information security company, hackers exploited 55 zero-day vulnerabilities in 2022. Zero-day vulnerabilities refer to security flaws in software that are publicly disclosed or exploited before the company responsible for patching it is aware of the issue. Due to the lack of protections or firewalls in place, [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/03/22/microsoft-google-apple-zero-day-vulnerabilities/">Microsoft, Google, and Apple among most exploited in 2022 zero-day vulnerabilities</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-300x200.webp?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="security-protection" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-300x200.webp 300w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1024x683.webp 1024w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-768x512.webp 768w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-696x464.webp 696w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1068x712.webp 1068w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-630x420.webp 630w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection.webp 1125w" sizes="(max-width: 300px) 100vw, 300px" />
<p>According to a recent report by Mandiant, a leading information security company, hackers exploited 55 zero-day <a href="https://www.gizmochina.com/tag/vulnerability/" target="_blank" rel="noreferrer noopener">vulnerabilities</a> in 2022. Zero-day vulnerabilities refer to security flaws in software that are publicly disclosed or exploited before the company responsible for patching it is aware of the issue. Due to the lack of protections or firewalls in place, hackers often take advantage of these vulnerabilities to carry out attacks.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="683" src="https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1024x683.webp?x44794" alt="security protection" class="wp-image-524352" srcset="https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1024x683.webp 1024w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-300x200.webp 300w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-768x512.webp 768w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-696x464.webp 696w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-1068x712.webp 1068w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection-630x420.webp 630w, https://www.gizmochina.com/wp-content/uploads/2023/03/security-protection.webp 1125w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>The report by Mandiant found that the three largest technology vendors in the world, <a href="https://www.gizmochina.com/tag/microsoft/" target="_blank" rel="noreferrer noopener">Microsoft</a>, <a href="https://www.gizmochina.com/tag/google/" target="_blank" rel="noreferrer noopener">Google</a>, and <a href="https://www.gizmochina.com/tag/apple/">Apple</a>, were the most commonly exploited vendors for the third year in a row, with 18, 10, and 9 zero-day vulnerabilities respectively. The most frequently affected product types were <a href="https://www.gizmochina.com/tag/operating-system/" target="_blank" rel="noreferrer noopener">operating systems</a> (19), <a href="https://www.gizmochina.com/tag/browser/" target="_blank" rel="noreferrer noopener">browsers</a> (11), <a href="https://www.gizmochina.com/tag/security/" target="_blank" rel="noreferrer noopener">security</a>, IT, and network management products (10), and mobile operating systems (6).</p>



<p>Interestingly, the report revealed that desktop operating systems were most exploited, with 19 zero-day vulnerabilities identified. Windows was the most affected, with 15 zero-day flaws, followed by macOS with four. In the case of mobile operating systems, 5 zero-day vulnerabilities were exploited in iOS and one in Android.</p>



<p>The report also highlights that China was the country that exploited the most zero-day vulnerabilities in 2022, followed by North Korea and Russia.</p>



<p>While the number of zero-day vulnerabilities exploited in 2022 decreased from the previous year, the report indicates that these kinds of exploits will likely continue. The report recommends that organizations take proactive measures to address these vulnerabilities, such as implementing security patches and conducting regular vulnerability assessments.</p>



<p>Recently, <a href="https://www.gizmochina.com/category/microsoft/" target="_blank" rel="noreferrer noopener">Microsoft</a> fixed a critical zero-day issue in Outlook that had been exploited by a hacker group to attack a number of <a href="https://www.gizmochina.com/tag/eu/" target="_blank" rel="noreferrer noopener">European government</a> and military organizations in 2022. It is important for organizations to remain vigilant and take necessary precautions to prevent potential zero-day vulnerabilities from being exploited by cybercriminals.</p>



<p><strong>RELATED:</strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/03/21/google-pixel-watch-improvements-new-features-latest-update/">Google Pixel Watch gets serious Improvements and New Features with latest Update</a></li><li><a href="https://www.gizmochina.com/2023/03/21/google-pixel-8-modified-samsung-chip/">Google Pixel 8 may be powered by a modified Samsung Exynos 2300 chip</a></li><li><a href="https://www.gizmochina.com/2023/03/21/google-identifies-malware-chinese-ecommerce-pinduoduo/">Google Identifies Malware in Popular Chinese E-Commerce Giant Pinduoduo’s Apps</a></li><li><a href="https://www.gizmochina.com/2023/03/21/google-pixel-8-design-renders-leak/">Google Pixel 8 series design compared to Pixel 7 series in latest leaked renders</a></li><li><a href="https://www.gizmochina.com/2023/03/21/google-pixel-6-5g-support-india/">Google Pixel 6 &amp; Pixel 6 Pro receives 5G support in India</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="OPPO FIND X6 PRO Review Part 1: Triple Main Cameras, All In One" width="696" height="392" src="https://www.youtube.com/embed/5HT-E0s54Os?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://www.mandiant.com/resources/blog/zero-days-exploited-2022" target="_blank" rel="noreferrer noopener">Source</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/03/22/microsoft-google-apple-zero-day-vulnerabilities/">Microsoft, Google, and Apple among most exploited in 2022 zero-day vulnerabilities</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google Reports 18 Vulnerabilities in Samsung Modems, Pixel Devices Also Affected</title>
		<link>https://www.gizmochina.com/2023/03/17/google-vulnerabilities-samsung-modems/</link>
		
		<dc:creator><![CDATA[Anubhav]]></dc:creator>
		<pubDate>Fri, 17 Mar 2023 04:41:21 +0000</pubDate>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Samsung]]></category>
		<category><![CDATA[Pixel]]></category>
		<category><![CDATA[Samsung Exynos]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=523162</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-300x169.webp?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Samsung Exynos" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-300x169.webp 300w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-1024x576.webp 1024w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-768x432.webp 768w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-1536x864.webp 1536w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-696x392.webp 696w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-1068x601.webp 1068w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-747x420.webp 747w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos.webp 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>Vulnerabilities with chipsets and phone modems can be exploited by attackers to gain unauthorized access to sensitive data, control the device remotely, or cause damage to the device or the user. This is why it is extremely essential to stay updated on security patches and updates from manufacturers to protect against such vulnerabilities and ensure [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/03/17/google-vulnerabilities-samsung-modems/">Google Reports 18 Vulnerabilities in Samsung Modems, Pixel Devices Also Affected</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-300x169.webp?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Samsung Exynos" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-300x169.webp 300w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-1024x576.webp 1024w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-768x432.webp 768w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-1536x864.webp 1536w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-696x392.webp 696w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-1068x601.webp 1068w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos-747x420.webp 747w, https://www.gizmochina.com/wp-content/uploads/2023/03/Exynos.webp 1920w" sizes="(max-width: 300px) 100vw, 300px" />
<p>Vulnerabilities with chipsets and phone modems can be exploited by attackers to gain unauthorized access to sensitive data, control the device remotely, or cause damage to the device or the user. This is why it is extremely essential to stay updated on security patches and updates from manufacturers to protect against such vulnerabilities and ensure the security of personal information and data. On March 17, the IT House reported that the Google Project Zero security team has recently discovered 18 vulnerabilities in <a href="http://gizmochina.com/category/samsung">Samsung</a> modems. These vulnerabilities affect several models of Samsung devices, including the Pixel 6 series, Pixel 7 series, Galaxy S22 series, and <a href="http://gizmochina.com/product/samsung-galaxy-a53/">Galaxy A53</a> models.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" width="1000" height="649" src="https://www.gizmochina.com/wp-content/uploads/2023/03/72d15155-a18b-4f20-9eb9-9597e8bafec2.webp?x44794" alt="Google Vulnerability" class="wp-image-523165" srcset="https://www.gizmochina.com/wp-content/uploads/2023/03/72d15155-a18b-4f20-9eb9-9597e8bafec2.webp 1000w, https://www.gizmochina.com/wp-content/uploads/2023/03/72d15155-a18b-4f20-9eb9-9597e8bafec2-300x195.webp 300w, https://www.gizmochina.com/wp-content/uploads/2023/03/72d15155-a18b-4f20-9eb9-9597e8bafec2-768x498.webp 768w, https://www.gizmochina.com/wp-content/uploads/2023/03/72d15155-a18b-4f20-9eb9-9597e8bafec2-696x452.webp 696w, https://www.gizmochina.com/wp-content/uploads/2023/03/72d15155-a18b-4f20-9eb9-9597e8bafec2-647x420.webp 647w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure></div>



<p>According to Google&#8217;s report, four of the 18 vulnerabilities are rated as &#8220;critical&#8221;. If exploited, attackers can remotely damage the victim&#8217;s phone without the need for any user interaction, as long as they have the phone number.</p>



<p>Google has already released a security update in March this year to fix this issue for Pixel phones. However, it&#8217;s worth noting that Google has not fixed the vulnerabilities for Pixel 6, <a href="http://gizmochina.com/product/google-pixel-6-pro/">Pixel 6 Pro</a>, and <a href="http://gizmochina.com/product/google-pixel-6a/">Pixel 6a</a>. Since the chipsets for these smartphones are fabricated on top of Samsung&#8217;s own chips, it is understandable that they will be affected by the same. </p>



<p>Affected devices include the following: Samsung branded phones such as <a href="http://gizmochina.com/product/samsung-galaxy-s22/">Galaxy S22</a>, M33, M13, M12, A71, A53, A33, A21, A13, A12, and A04 series, <a href="http://gizmochina.com/category/vivo">vivo</a>-branded phones such as <a href="http://gizmochina.com/product/vivo-s16/">S16</a>, S15, S6, X70, X60, and X30 series, Google phones such as <a href="http://gizmochina.com/product/google-pixel-6/">Pixel 6</a> series and <a href="http://gizmochina.com/product/google-pixel-7/">Pixel 7</a> series, any wearable device using the <a href="http://gizmochina.com/tag/exynos">Exynos</a> W920 chipset, and any vehicle using the Exynos Auto T5123 chipset.</p>



<p>Users should stay vigilant and make sure to update their devices to the latest software versions as soon as possible to ensure the security of their data and personal information.</p>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/03/16/google-pixel-7a-prototype-selling-ebay/">Alleged Google Pixel 7a prototype Selling on eBay months before Launch</a></li><li><a href="https://www.gizmochina.com/2023/01/23/samsung-galaxy-app-store-malware-fix/">Samsung Releases Galaxy App Store Update To Fix Malware Vulnerability</a></li><li><a href="https://www.gizmochina.com/guides/best-tablets-under-150-samsung-teclast-and-others/">Best Tablets Under $150: Samsung, Teclast, and others</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Insta360 X3 360° Action Camera Review: A Revolutionary Versatile Camera For Everyone" width="696" height="392" src="https://www.youtube.com/embed/md8XFSC0CMQ?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://www.ithome.com/0/680/301.htm">Source</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/03/17/google-vulnerabilities-samsung-modems/">Google Reports 18 Vulnerabilities in Samsung Modems, Pixel Devices Also Affected</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EarSpy let&#8217;s you eavesdrop on phone conversations via motion sensors</title>
		<link>https://www.gizmochina.com/2023/01/02/earspy-eavesdrop-phone-conversation/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Mon, 02 Jan 2023 11:56:40 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[EarSpy]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=506265</guid>

					<description><![CDATA[<img width="300" height="166" src="https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy-300x166.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="EarSpy" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy-300x166.png 300w, https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy.png 422w" sizes="(max-width: 300px) 100vw, 300px" /><p>Researchers have just developed an interesting new technology for side channel attacks on smartphones. It is called EarSpy and it is capable of eavesdropping on your phone conversations through the handset&#8217;s built in motion sensors. This tech was developed by a group of researchers from the University of Dayton, New Jersey Institute of Technology, Rutgers [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/01/02/earspy-eavesdrop-phone-conversation/">EarSpy let&#8217;s you eavesdrop on phone conversations via motion sensors</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="166" src="https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy-300x166.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="EarSpy" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy-300x166.png 300w, https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy.png 422w" sizes="(max-width: 300px) 100vw, 300px" />
<p>Researchers have just developed an interesting new technology for side channel attacks on smartphones. It is called EarSpy and it is capable of eavesdropping on your phone conversations through the handset&#8217;s built in motion sensors.</p>



<p>This tech was developed by a group of researchers from the University of Dayton, New Jersey Institute of Technology, Rutgers University, Texas A&amp;M University, and Temple University. As per their report, the researchers had managed to record vibrations from a phone&#8217;s loudspeaker in the past. But now, the new method of attack can even map the vibrations coming from the smartphone&#8217;s earpiece. So your conversations can be caught even when you&#8217;re talking with the phone on your ear.</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" width="422" height="234" src="https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy.png?x44794" alt="EarSpy" class="wp-image-506275" srcset="https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy.png 422w, https://www.gizmochina.com/wp-content/uploads/2023/01/EarSpy-300x166.png 300w" sizes="(max-width: 422px) 100vw, 422px" /></figure></div>



<p>The findings were shared on SecurityWeek and EarSpy was tested on the OnePlus 7T and the OnePlus 9 models. Interestingly enough, the results were surprisingly accurate and were made through data that was taken from nothing but the earpiece and the built in accelerometer. Fortunately, older OnePlus models were safe in this regard, but this was due to their lack of stereo speakers as per the research paper. The group recorded and analyzed the reverberations from ear  speaker with the help of spectrograms and time-frequency domain feature extraction. </p>



<p>Apart from just capturing the words, the team also worked on identifying gender of the speaker as well. To take things further, there is also a potential risk of this technology being able to determine the identity of the speaker. While new Android versions have a strong security measures against malware, EarSpy is able to bypass all of these security features since the raw data from a smartphone&#8217;s motion sensors is a lot more easily accessible. The researchers have noted that smartphone brands should position the motion sensors away from any source of vibrations to reduce the risk of this vulnerability.</p>



<p><strong>RELATED:</strong></p>



<ul><li><a href="https://www.gizmochina.com/2022/11/28/personal-information-of-500-million-whatsapp-users-has-stolen/">Personal Information of 500 Million WhatsApp Users Has Been Stolen</a></li><li><a href="https://www.gizmochina.com/2022/05/24/apple-iphone-vulnerable-hacking-powered-off/">Apple iPhones are most vulnerable to hacking when powered off</a></li><li><a href="https://www.gizmochina.com/2022/12/10/hacker-didnt-even-take-a-minute-to-hack-galaxy-s22/">Hacker Didn’t Even Take a Minute to Hack Galaxy S22; Broke All the Records</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="Xiaomi 13 Pro Full Review Part 2: Camera Test" width="696" height="392" src="https://www.youtube.com/embed/LSsWlRO4B7Q?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://www.androidpolice.com/earspy-attack-eavesdrop-using-motion-sensors/" target="_blank" rel="noreferrer noopener">Via</a>, <a href="https://www.securityweek.com/earspy-spying-phone-calls-ear-speaker-vibrations-captured-accelerometer" target="_blank" rel="noreferrer noopener">Source</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/01/02/earspy-eavesdrop-phone-conversation/">EarSpy let&#8217;s you eavesdrop on phone conversations via motion sensors</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPhone, iPads face new vulnerabilities in latest iOS &#038; iPadOS</title>
		<link>https://www.gizmochina.com/2022/10/27/apple-ipad-iphone-security-vulnerability/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 27 Oct 2022 11:00:14 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iOS 16]]></category>
		<category><![CDATA[iPad]]></category>
		<category><![CDATA[iPadOS 16]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=492603</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x.jpg 1312w" sizes="(max-width: 300px) 100vw, 300px" /><p>Apple recently released the new iOS 16.1 and iPadOS 16.1 updates for its iPhones and iPads. New updates usually bring some small bugs and glitches, but this time aaround, it appears that the new updates also come with some serious security flaws as well. According to an Economic Times report, iPhone and iPads have been [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/10/27/apple-ipad-iphone-security-vulnerability/">Apple iPhone, iPads face new vulnerabilities in latest iOS &amp; iPadOS</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x.jpg 1312w" sizes="(max-width: 300px) 100vw, 300px" />
<p><a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noreferrer noopener">Apple </a>recently released the new iOS 16.1 and iPadOS 16.1 updates for its iPhones and iPads. New updates usually bring some small bugs and glitches, but this time aaround, it appears that the new updates also come with some serious security flaws as well.</p>



<p>According to an <em><a href="https://telecom.economictimes.indiatimes.com/news/cert-in-warns-of-multiple-vulnerabilities-in-iphones-ipads/95109515" target="_blank" rel="noreferrer noopener">Economic Times </a></em>report, iPhone and iPads have been facing vulnerabilities due to the new iOS and iPadOS updates. The information arrives from an advisory by the Indian Computer Emergency Response Team (Cert-IN). This report stated that the latest iOS and iPadOS builds feature a number of new vulnerabilities that would allow hackers with malicious intent to remotely access a user’s private data, run arbitrary code and spoof the interface address. Furthermore, these hackers could possibly even run denial of service programs remotely on the victim&#8217;s iPhone or iPad.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="576" src="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg?x44794" alt="Apple" class="wp-image-492605" srcset="https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1024x576.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-1068x601.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2022/10/Apple_ipadair-iphone12pro-iphone12_10212020.jpg.landing-big_2x.jpg 1312w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>As per Cert-IN, several iPhones from the Cupertino based giant are vulnerable to cyberattacks if they are running on iOS 16.1 and iOS 16.0.3 builds. Similarly, the security flaw also affects iPads running on iPadOS versions prior to the iPadOS 16.1 build. Due to this issue, the Apple iPhone 8 and after models are affected, while the iPad Pro Call models, iPad Air 3rd Gen and later, iPad 5th Gen and later, and even the iPad mini 5th gen and newer models are also among the list of affected devices.</p>



<p>Cert-IN stated that the severity of these vulnerabilities is high and is caused because of inadequate security controls in the AppleMobileFileIntegrity component among a number of other factors as well. Now, hackers could exploit these vulnerabilities by having the user open a malicious file or application. These files or apps would include harmful firmware that could help the hacker gain access to the victim&#8217;s device.</p>



<p><strong>RELATED:</strong></p>



<ul><li><a href="https://www.gizmochina.com/2022/10/26/iphone-15-usb-c-port-apple-complies-eu/">iPhone 15 to launch with USB-C port, as Apple complies with EU law: Report</a></li><li><a href="https://www.gizmochina.com/2022/10/25/apple-launch-macbook-pro-mac-mini-soon/">Apple may launch new MacBook Pro and Mac mini models in the coming months</a></li><li><a href="https://www.gizmochina.com/2022/10/25/apple-releases-ipados-16/">Apple releases iPadOS 16 with Stage Manager, Weather app, and more</a></li><li><a href="https://www.gizmochina.com/2022/10/24/apple-iphone-15-ultra-kill-base-iphone/">Apple iPhone 15 Ultra might kill off the 6.1 inch base iPhone model</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="uleFone Armor 17 Pro Review: MagSafe, with a rugged phone" width="696" height="392" src="https://www.youtube.com/embed/cyPtnCmxnn4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
</div></figure>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/10/27/apple-ipad-iphone-security-vulnerability/">Apple iPhone, iPads face new vulnerabilities in latest iOS &amp; iPadOS</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Motorola smartphones reportedly at risk of hacking with chip-level vulnerability</title>
		<link>https://www.gizmochina.com/2022/06/06/motorola-smartphones-chip-level-vulnerability/</link>
		
		<dc:creator><![CDATA[Jeet]]></dc:creator>
		<pubDate>Mon, 06 Jun 2022 06:48:04 +0000</pubDate>
				<category><![CDATA[Motorola]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[UNISOC]]></category>
		<category><![CDATA[Chip]]></category>
		<category><![CDATA[Chipset]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Unisoc]]></category>
		<category><![CDATA[Unisoc T700]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=464117</guid>

					<description><![CDATA[<img width="300" height="188" src="https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-300x188.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Moto G20 Sky Blue" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-300x188.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-768x480.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1024x640.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-696x435.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1068x668.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-672x420.jpg 672w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1920x1200.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>Unisoc, a China-based chip manufacturer, has been able to take advantage of the opportunity presented by the global chip shortage and is now aiming to replace MediaTek in the budget smartphones segment as the Taiwan-based company is focusing on capturing the premium market. With such a rise, the company also goes through stricter scrutiny. While some [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/06/06/motorola-smartphones-chip-level-vulnerability/">Motorola smartphones reportedly at risk of hacking with chip-level vulnerability</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="188" src="https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-300x188.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Moto G20 Sky Blue" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-300x188.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-768x480.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1024x640.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-696x435.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1068x668.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-672x420.jpg 672w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1920x1200.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p><a href="https://www.gizmochina.com/tag/unisoc">Unisoc</a>, a China-based chip manufacturer, has been able to take advantage of the opportunity presented by the global chip shortage and is now aiming to replace <a href="https://www.gizmochina.com/tag/motorola">MediaTek</a> in the budget smartphones segment as the Taiwan-based company is focusing on capturing the premium market.</p>
<p>With such a rise, the company also goes through stricter scrutiny. While some of the company&#8217;s older <a href="https://www.gizmochina.com/tag/chip">chips</a> were marked as a threat vector, now another vulnerability has been found that explicitly affects a Unisoc chip found in three Motorola devices.</p>
<p><img loading="lazy" class="aligncenter wp-image-385684 size-full" src="https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue.jpg?x44794" alt="Moto G20 Sky Blue" width="3200" height="2000" srcset="https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue.jpg 3200w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-300x188.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-768x480.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1024x640.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-696x435.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1068x668.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-672x420.jpg 672w, https://www.gizmochina.com/wp-content/uploads/2021/04/Moto-G20-Sky-Blue-1920x1200.jpg 1920w" sizes="(max-width: 3200px) 100vw, 3200px" /></p>
<p>According to the <a href="https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/">report from <em>Checkpoint Research</em></a>, the Unisoc Tiger T700 chip, which powers the Motorola Moto G20, E30, and E40 smartphones, has been found to have a vulnerability w<span style="font-family: Verdana, BlinkMacSystemFont, -apple-system, 'Segoe UI', Roboto, Oxygen, Ubuntu, Cantarell, 'Open Sans', 'Helvetica Neue', sans-serif">hen the cellular <a href="https://www.gizmochina.com/tag/modem">modem</a> attempts to connect to an LTE network.</span></p>
<p><span style="font-family: Verdana, BlinkMacSystemFont, -apple-system, 'Segoe UI', Roboto, Oxygen, Ubuntu, Cantarell, 'Open Sans', 'Helvetica Neue', sans-serif">It basically omits the check to make sure that the modem&#8217;s connection handler is reading a valid IMSI or similar subscriber ID. When the handler reads a zero-digit field, a stack overflow occurs which can be exploited for a denial of service attack or for remote code execution, blocking the user from the <a href="https://www.gizmochina.com/tag/lte">LTE network</a>.</span></p>
<p>Checkpoint Research notified Unisoc about this last month and the company evaluated it to be of critical risk with a 9.4 out of 10 ratings and promptly patched the issue. <a href="https://www.gizmochina.com/tag/google">Google</a> may pass the patch onto users soon, likely with the new <a href="https://www.gizmochina.com/tag/android">Android</a> security bulletin.</p>
<p>There haven&#8217;t been any reports of this flaw getting exploited but this is still a large problem, especially because most Unisoc <a href="https://www.gizmochina.com/tag/processor">processors</a> are used in budget smartphones that rarely get new software updates.</p>
<p><strong>RELATED: </strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/05/23/motorola-teases-phone-200mp-camera-launching-july/">Motorola teases a phone with 200MP camera launching in July</a></li>
<li><a href="https://www.gizmochina.com/2022/05/23/motorola-razr-3-might-be-the-first-snapdragon-8-plus-gen-1-powered-foldable-phone/">Motorola Razr 3 might be the first Snapdragon 8 Plus Gen 1-powered foldable phone</a></li>
<li><a href="https://www.gizmochina.com/2022/05/30/motorola-moto-g42-with-snapdragon-680-soc-appears-on-geekbench/">Motorola Moto G42 with Snapdragon 680 SoC appears on Geekbench</a></li>
<li><a href="https://www.gizmochina.com/2022/05/09/motorola-rollable-display-phone-codenamed-felix-in-works/">Motorola rollable display phone codenamed Felix in works</a></li>
<li><a href="https://www.gizmochina.com/2022/05/12/motorola-edge-30-india-launch-price-specs/">Motorola Edge 30 launched in India with Snapdragon 778G Plus SoC, 144Hz pOLED display, 6.79mm thickness, and more</a></li>
</ul>
<p><iframe loading="lazy" title="AGM Glory G1S Review: A thermal imaging camera that can make phone calls" width="696" height="392" src="https://www.youtube.com/embed/hSIDq2c1a8E?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/06/06/motorola-smartphones-chip-level-vulnerability/">Motorola smartphones reportedly at risk of hacking with chip-level vulnerability</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPhones are most vulnerable to hacking when powered off</title>
		<link>https://www.gizmochina.com/2022/05/24/apple-iphone-vulnerable-hacking-powered-off/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Tue, 24 May 2022 10:43:33 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple iPhone]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=462068</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-300x169.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="iPhone 13 Pro Series" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured.png 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>While iPhones are typically seen as one of the more secure smartphones in the market by many consumers, it appears that the Apple device is still quite prone to hacking. This is apparently true especially when they are turned off. According to a research report from Technical University of Darmstadt, the iPhones are the most [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/05/24/apple-iphone-vulnerable-hacking-powered-off/">Apple iPhones are most vulnerable to hacking when powered off</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-300x169.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="iPhone 13 Pro Series" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-747x420.png 747w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured.png 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>While iPhones are typically seen as one of the more secure smartphones in the market by many consumers, it appears that the <a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noopener">Apple</a> device is still quite prone to hacking. This is apparently true especially when they are turned off.</p>
<p><img loading="lazy" class="aligncenter wp-image-433650 size-full" src="https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured.png?x44794" alt="Apple" width="1920" height="1080" srcset="https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured.png 1920w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-768x432.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-1024x576.png 1024w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-696x392.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-1068x601.png 1068w, https://www.gizmochina.com/wp-content/uploads/2021/12/iPhone-13-Pro-series-featured-747x420.png 747w" sizes="(max-width: 1920px) 100vw, 1920px" /></p>
<p>According to a <a href="https://arxiv.org/pdf/2205.06114.pdf">research report</a> from Technical University of Darmstadt, the iPhones are the most vulnerable to hackers when they are switched off. The primary reason for this is due to how it handles its various wireless networking technologies. When an iPhone is switched off, most wireless chips, like Bluetooth, NFC (Near Field Communications), and UWB (Ultra Wideband) are still running up to 24 hours. Although, this is not some bug and does serve a crucial purpose as well.</p>
<p>The Cupertino based giant offers the Find My network function on their products, which helps in locating Apple owners’ products when they are lost or possibly even stolen. This also lets you still have access to items like credit cards, student passes, and digital keys as well. But unfortunately, this feature is a double edged sword since these wireless chips have direct access to the secure elements. In other words, it could be potentially exploited by hackers to install malware on the iPhones even when the iOS system is not running.</p>
<p><img loading="lazy" class="aligncenter wp-image-297549 size-full" src="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg?x44794" alt="Apple" width="620" height="414" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w, https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w" sizes="(max-width: 620px) 100vw, 620px" /></p>
<p>These wireless chips remain active in a Low Power Mode (LPM). However, this LPM support is implemented on a hardware level. So, this can not be simply fixed via an OTA software update. The researchers conducted a security analysis of LPM features introduced with iOS 15 and found that Bluetooth LPM firmware can be modified to run malware on the iPhone. This enables hackers to have system level access to track someone’s location or run new features on their phone. Fortunately for many, this mostly affects jailbroken iPhones. Although, the security hole might still be used as spyware to target people.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2022/05/23/apple-plans-to-shift-manufacturing-outside-china-report/" target="_blank" rel="noopener">Apple plans to shift manufacturing outside China: Report</a></li>
<li><a href="https://www.gizmochina.com/2022/05/21/apple-iphones-with-esim-face-bug-that-deactivates-facetime-imessage/" target="_blank" rel="noopener">Apple iPhones with eSIM face bug that deactivates FaceTime &amp; iMessage</a></li>
<li><a href="https://www.gizmochina.com/2022/05/20/apple-iphone-shipment-rise-q1-2022-north-america/" target="_blank" rel="noopener">Apple iPhone shipments rises by almost 20% in Q1 2022 in North America</a></li>
</ul>
<p><iframe loading="lazy" title="Dangbei Mars Pro Review: The best budget Laser projector" width="696" height="392" src="https://www.youtube.com/embed/h_H0Lzz8bc0?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2022/05/24/apple-iphone-vulnerable-hacking-powered-off/">Apple iPhones are most vulnerable to hacking when powered off</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MediaTek chips had faced a vulnerability that allowed apps to eavesdrop on users</title>
		<link>https://www.gizmochina.com/2021/11/24/mediatek-chips-vulnerability-let-apps-eaverdrop/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Wed, 24 Nov 2021 20:13:58 +0000</pubDate>
				<category><![CDATA[MediaTek]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Dimensity]]></category>
		<category><![CDATA[Mediatek]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=427012</guid>

					<description><![CDATA[<img width="300" height="129" src="https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-300x129.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="MediaTek" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-300x129.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-768x331.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-1024x441.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-696x300.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-1068x460.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-974x420.jpg 974w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000.jpg 1220w" sizes="(max-width: 300px) 100vw, 300px" /><p>Earlier today (25th November 2021), a vulnerability was spotted in the AI and audio processing components in recently launched MediaTek chipsets. This vulnerability would&#8217;ve allowed apps to eavesdrop on users. According to an AndroidPolice report, Check Point Research had discovered the vulnerability, which allows &#8220;local privilege escalation attack&#8221; from a third party application. To put [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/11/24/mediatek-chips-vulnerability-let-apps-eaverdrop/">MediaTek chips had faced a vulnerability that allowed apps to eavesdrop on users</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="129" src="https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-300x129.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="MediaTek" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-300x129.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-768x331.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-1024x441.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-696x300.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-1068x460.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000-974x420.jpg 974w, https://www.gizmochina.com/wp-content/uploads/2021/05/gsmarena_000.jpg 1220w" sizes="(max-width: 300px) 100vw, 300px" /><p>Earlier today (25th November 2021), a vulnerability was spotted in the AI and audio processing components in recently launched <a href="https://www.gizmochina.com/tag/mediatek/" target="_blank" rel="noopener noreferrer">MediaTek</a> chipsets. This vulnerability would&#8217;ve allowed apps to eavesdrop on users.</p>
<p>According to an <a href="https://www.androidpolice.com/mediatek-vulnerability-eavesdrop/" target="_blank" rel="noopener noreferrer"><em>AndroidPolice</em> </a>report, Check Point Research had discovered the vulnerability, which allows &#8220;local privilege escalation attack&#8221; from a third party application. To put things simply, an app loaded with the right code could possibly have gained access to AI and audio related information that it otherwise wouldn&#8217;t have had access to. Fortunately, the Taiwanese chipmaker fixed the issue before it was exploited. The company has even fixed every related vulnerabilities as of October 2021.</p>
<p><img loading="lazy" class="aligncenter wp-image-426469 size-full" src="https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110.jpg?x44794" alt="MediaTeK Dimensity 9000" width="1280" height="640" srcset="https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110.jpg 1280w, https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110-300x150.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110-768x384.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110-1024x512.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110-696x348.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110-1068x534.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2021/11/20211122193110-840x420.jpg 840w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>
<p>While the process to exploit this vulnerability was quite complicated, the issue would&#8217;ve given any apps to pass specific commands to the audio interface. This would&#8217;ve been a major issue considering MediaTek had a notable 43 percent market share in the smartphone process market as of the second quarter of this year. In other words, the company was the <a href="https://www.gizmochina.com/2021/11/12/mediatek-is-the-largest-smartphone-soc-maker-ceo/" target="_blank" rel="noopener noreferrer">number one brand for smartphone chips</a> in terms of shipments. So, the vulnerability could&#8217;ve been disastrous for the company. Although, the issue has reportedly been fixed back in October, so it is recommended that MediaTek users update their devices to the latest patches just to be on the safer side.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2021/11/23/redmi-k50-series-to-offer-4-different-processors-from-qualcomm-mtk/" target="_blank" rel="noopener noreferrer">Redmi K50 series to come with four different processors from both Qualcomm and MediaTek</a></li>
<li><a href="https://www.gizmochina.com/2021/11/22/mediateks-vp-claims-dimensity-9000-squares-apple-a15-bionic-benchmark-tests/" target="_blank" rel="noopener noreferrer">MediaTek&#8217;s VP claims the Dimensity 9000 squares up with Apple A15 Bionic in benchmark tests</a></li>
<li><a href="https://www.gizmochina.com/2021/11/22/mediatek-dimensity-7000-75w-rumors/" target="_blank" rel="noopener noreferrer">MediaTek Dimensity 7000 5nm chip to reportedly have 75W fast charging support</a></li>
<li><a href="https://www.gizmochina.com/2021/11/20/mediatek-aims-for-premium-chromebook-market-with-kompanio-1200-chip/" target="_blank" rel="noopener noreferrer">MediaTek aims for premium Chromebook market with its Kompanio 1200 chip in 2022</a></li>
</ul>
<p><iframe loading="lazy" title="Dreametech W10 Robot Vacuum Cleaner and Mop: Frees you from housework" width="696" height="392" src="https://www.youtube.com/embed/dEPR8CdrlR8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/11/24/mediatek-chips-vulnerability-let-apps-eaverdrop/">MediaTek chips had faced a vulnerability that allowed apps to eavesdrop on users</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>BrakTooth vulnerabilities affects massive number of Bluetooth enabled products</title>
		<link>https://www.gizmochina.com/2021/09/07/braktooth-vulnerabilities-affect-bluetooth-products/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Tue, 07 Sep 2021 11:49:23 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[BrakTooth]]></category>
		<category><![CDATA[IoT products]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=410867</guid>

					<description><![CDATA[<img width="300" height="168" src="https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-300x168.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="BrakTooth" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-300x168.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-768x430.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-696x390.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-750x420.png 750w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171.png 946w" sizes="(max-width: 300px) 100vw, 300px" /><p>Researchers at the Singapore University of Technology and Design have recently discovered a family of 20 vulnerabilities that they have collectively labelled as BrakTooth. This affects more than 1,400 products based on 13 different Bluetooth devices from various major brands. According to the researchers (Via PCMag), the security flaw has been confirmed to affect over [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/09/07/braktooth-vulnerabilities-affect-bluetooth-products/">BrakTooth vulnerabilities affects massive number of Bluetooth enabled products</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="168" src="https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-300x168.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="BrakTooth" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-300x168.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-768x430.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-696x390.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-750x420.png 750w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171.png 946w" sizes="(max-width: 300px) 100vw, 300px" /><p>Researchers at the Singapore University of Technology and Design have recently discovered a family of 20 vulnerabilities that they have collectively labelled as BrakTooth. This affects more than 1,400 products based on 13 different Bluetooth devices from various major brands.</p>
<p><img loading="lazy" class="size-full wp-image-410882 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171.png?x44794" alt="BrakTooth" width="946" height="530" srcset="https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171.png 946w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-300x168.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-768x430.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-696x390.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/09/Screenshot-171-750x420.png 750w" sizes="(max-width: 946px) 100vw, 946px" /></p>
<p>According to the <a href="https://asset-group.github.io/disclosures/braktooth/" target="_blank" rel="noopener noreferrer"><em>researchers</em> </a>(Via <a href="https://in.pcmag.com/security/144698/braktooth-vulnerabilities-affect-countless-bluetooth-devices" target="_blank" rel="noopener noreferrer"><em>PCMag</em></a>), the security flaw has been confirmed to affect over 1,400 smartphones, laptops, keyboards, headphones, and other Bluetooth enabled devices. Although, the researchers claimed that this is just a low ball figure as &#8220;the BT stack is often shared across many products,&#8221; and that &#8220;it is highly probable that many other products (beyond the ≈1400 entries observed in Bluetooth listing) are affected by BrakTooth.&#8221;</p>
<p>This series of vulnerabilities can apparently be exploited to conduct denial of service (DoS) attacks and enable arbitrary code execution (ACE) on target devices. These DoS attacks can disrupt the victim&#8217;s Bluetooth connection or could even require Bluetooth connectivity to be manually restarted to function normally again. Furthermore, ACE can also be used to erase user data, disable wireless connectivity, or interact with other devices as well.</p>
<p><iframe loading="lazy" title="BrakTooth - Feature Response Flooding on Audio Products" width="696" height="392" src="https://www.youtube.com/embed/AekAMurR5Kk?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>As of right now, BrakTooth is only capable of enabling ACE on the ESP32 system on chip (SoC) made by Espressif Systems. Although, these chips are commonly found in IoT products as well as industrial systems. The researchers noted that this SoC is so common that proof of concept exploit actually uses an ESP32 development kit to conduct attacks on target devices. At the moment, the researchers have informed the various top vendors of this exploit and certain companies have already released firmware patches to fix the vulnerabilities while others are investigating the issue.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2021/06/17/tim-cook-blames-app-side-loading-for-android-malware/" target="_blank" rel="noopener noreferrer">Tim Cook blames app side oading for Android having more malware than iOS</a></li>
<li><a href="https://www.gizmochina.com/2021/06/11/ea-suffers-breach-hacker-sell-fifa-21-source-code/" target="_blank" rel="noopener noreferrer">EA suffers a Data Breach, with hackers now selling FIFA 21 source code</a></li>
<li><a href="https://www.gizmochina.com/2021/08/27/1-million-gamers-exposed-hackers-china-developer/" target="_blank" rel="noopener noreferrer">Over 1 million Gamers exposed to hackers by known Android game developer from China</a></li>
</ul>
<p><iframe loading="lazy" title="Lenovo Xiaoxin Pad Pro 2021 vs Xiaomi Mi Pad 5 Pro tablets comparison: Unexpected Results!" width="696" height="392" src="https://www.youtube.com/embed/5IRY-_IjDkg?start=5&#038;feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/09/07/braktooth-vulnerabilities-affect-bluetooth-products/">BrakTooth vulnerabilities affects massive number of Bluetooth enabled products</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPad Pro with M1 chips have an irreparable security flaw</title>
		<link>https://www.gizmochina.com/2021/05/27/apple-m1-ipad-pro-irreparable-security-flaw/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 27 May 2021 08:54:48 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[iPad Pro]]></category>
		<category><![CDATA[M1 chip]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=391725</guid>

					<description><![CDATA[<img width="300" height="168" src="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple M1 Chip" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-768x429.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1024x573.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-696x389.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1068x597.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-751x420.jpg 751w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1920x1074.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>The propriety M1 Chip from Apple has already made its way to a number of the company&#8217;s products. This includes MacBooks, iMacs, iMac mini, and even the iPad Pro. Now, a new report has found that the iPad Pro with the company&#8217;s silicon has an irreparable security flaw. According to developer Hector Martin (Via PhoneArena), [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/05/27/apple-m1-ipad-pro-irreparable-security-flaw/">Apple iPad Pro with M1 chips have an irreparable security flaw</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="168" src="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple M1 Chip" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-300x168.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-768x429.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1024x573.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-696x389.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1068x597.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-751x420.jpg 751w, https://www.gizmochina.com/wp-content/uploads/2020/11/20201110_211202-1920x1074.jpg 1920w" sizes="(max-width: 300px) 100vw, 300px" /><p>The propriety <a href="https://www.gizmochina.com/tag/apple-m1/" target="_blank" rel="noopener noreferrer">M1 Chip</a> from <a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noopener noreferrer">Apple</a> has already made its way to a number of the company&#8217;s products. This includes MacBooks, iMacs, iMac mini, and even the iPad Pro. Now, a new report has found that the iPad Pro with the company&#8217;s silicon has an irreparable security flaw.</p>
<p><img loading="lazy" class="aligncenter wp-image-353316 size-full" src="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png?x44794" alt="Apple m1 chip" width="715" height="402" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png 715w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-696x391.png 696w" sizes="(max-width: 715px) 100vw, 715px" /></p>
<p>According to developer <a href="https://m1racles.com/" target="_blank" rel="nofollow noopener noreferrer">Hector Martin</a> (Via <a href="https://www.phonearena.com/news/apple-m1-security-vulnerability_id132376" target="_blank" rel="noopener noreferrer">PhoneArena</a>), the M1 based iPad Pro suffers from a vulnerability that exists on a hardware level of the M1. In other words, this is an issue that cannot be fixed through a simple software update. The Cupertino based giant has apparently violated an Arm architecture specification requirement as well. This means that there is no simple method of fixing the issue.</p>
<p>The developer further explained that the flaw basically allows two applications to covertly exchange data without using normal operating system features. While this is a vulnerability, it, fortunately, does not pose any serious security risks. Even in a worst case scenario this security risk would only enable advertisers for cross app tracking and can not be used by hackers to take control of one&#8217;s device or even steal sensitive information. Although, the flaw still violates the OS security model.</p>
<p><img loading="lazy" class="aligncenter wp-image-385382 size-full" src="https://www.gizmochina.com/wp-content/uploads/2021/04/image.png?x44794" alt="Apple iPad Pro" width="817" height="435" srcset="https://www.gizmochina.com/wp-content/uploads/2021/04/image.png 817w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-300x160.png 300w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-768x409.png 768w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-696x371.png 696w, https://www.gizmochina.com/wp-content/uploads/2021/04/image-789x420.png 789w" sizes="(max-width: 817px) 100vw, 817px" /></p>
<p>Furthermore, this issue affects every M1 device, which means it could even affect the <a href="https://www.gizmochina.com/tag/iphone-12/" target="_blank" rel="noopener noreferrer">iPhone 12</a> series as well since the <a href="https://www.gizmochina.com/tag/apple-a14/" target="_blank" rel="noopener noreferrer">A14 Bionic</a> is based on the same CPU microarchitecture. The developer said that the only way of fixing this is to run the entire operating system as a virtual machine (VM). But that is not exactly a feasible repair to the issue. Hector believes that the flaw could even affect the next generation <a href="https://www.gizmochina.com/tag/m1x-chip/" target="_blank" rel="noopener noreferrer">M1X chipset</a> as well, but will be fixed in the following generation in the future.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2021/05/26/xiaomi-overtake-apple-q2-emerge-worlds-no-1-phone-maker/" target="_blank" rel="noopener noreferrer">Xiaomi hopes to overtake Apple in Q2 &amp;amp; to emerge world&#8217;s no. 1 phone maker in 3-5 years&#8217; time</a></li>
<li><a href="https://www.gizmochina.com/2021/05/26/apple-m1x-mac-mini-thinner-chassis-magnetic-connector/" target="_blank" rel="noopener noreferrer">Apple M1X Mac mini to feature thinner chassis and new iMac&#8217;s magnetic power connector: Report</a></li>
<li><a href="https://www.gizmochina.com/2021/05/26/apple-patent-iphone-display-glass-thinner-stronger/" target="_blank" rel="noopener noreferrer">Apple working on a way to make iPhone display glass thinner and stronger: Patent</a></li>
</ul>
<p><iframe loading="lazy" title="Xiaomi Flipbuds Pro Full Review: The strongest Xiaomi earbuds so far" width="696" height="392" src="https://www.youtube.com/embed/9-Z-09P0iR4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/05/27/apple-m1-ipad-pro-irreparable-security-flaw/">Apple iPad Pro with M1 chips have an irreparable security flaw</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Over 500 million Facebook users&#8217; phone numbers and personal data leaked</title>
		<link>https://www.gizmochina.com/2021/04/05/500-million-facebook-users-phone-numbers-data-leaked/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Mon, 05 Apr 2021 09:25:01 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[user data]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=381953</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Facebook" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b.jpg 1024w" sizes="(max-width: 300px) 100vw, 300px" /><p>It has recently been found that the personal data and phone numbers of hundreds of millions of Facebook users has been leaked online. All of this information was posted on a low level hacking forum that was found recently. According to a BusinessInsider report, the leaked data includes personal information and the phone numbers of [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/04/05/500-million-facebook-users-phone-numbers-data-leaked/">Over 500 million Facebook users&#8217; phone numbers and personal data leaked</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Facebook" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b.jpg 1024w" sizes="(max-width: 300px) 100vw, 300px" /><p>It has recently been found that the personal data and phone numbers of hundreds of millions of <a href="https://www.gizmochina.com/tag/facebook/" target="_blank" rel="noopener noreferrer">Facebook</a> users has been leaked online. All of this information was posted on a low level hacking forum that was found recently.</p>
<p><img loading="lazy" class="aligncenter wp-image-214085 size-full" src="https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b.jpg?x44794" alt="Facebook" width="1024" height="683" srcset="https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/09/26405898387_5e9e0c2c56_b-768x512.jpg 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></p>
<p>According to a <a href="https://www.businessinsider.in/tech/news/533-million-facebook-users-phone-numbers-and-personal-data-have-been-leaked-online/articleshow/81889315.cms" target="_blank" rel="noopener noreferrer"><em>BusinessInsider</em> </a>report, the leaked data includes personal information and the phone numbers of 533 million users of the popular social media platform. The data is from about 106 countries, including information on 32 million users from the US, 11 million users from the UK, 6 million users from India, and more. In the leak, personal data includes the users phone numbers, Facebook IDs, full names, location, birth dates, bios, and even email addresses in certain cases.</p>
<p>As per a statement from Facebook spokesperson, the data found online is actually scrapped due to a vulnerability that the company had patched back in 2019. Although, despite the information being dated, the information could still provide valuable information to cybercriminals that can use this information to impersonate people and scam others to handover login credentials as well.</p>
<p><img loading="lazy" class="aligncenter wp-image-297549 size-full" src="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg?x44794" alt="Facebook" width="620" height="414" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w, https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w" sizes="(max-width: 620px) 100vw, 620px" /></p>
<p>Alon Gal, CTO of cybercrime intelligence firm Hudson Rock stated that &#8220;A database of that size containing the private information such as phone numbers of a lot of Facebook&#8217;s users would certainly lead to bad actors taking advantage of the data to perform social engineering attacks [or] hacking attempts.&#8221; Gal further added that there is not much the company can do at this point as the information is already out in the open, but has advised users to be wary of phishing schemes or fraud.</p>
<p><strong>RELATED:</strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2021/03/23/facebook-says-it-pulled-down-1-3-billion-fake-accounts-between-oct-dec-2020/" target="_blank" rel="noopener noreferrer">Facebook says it pulled down 1.3 billion fake accounts between Oct. &#038; Dec. 2020</a></li>
<li><a href="https://www.gizmochina.com/2021/03/16/facebook-signs-its-first-deal-to-pay-news-corp-to-use-its-content-in-australia/" target="_blank" rel="noopener noreferrer">Facebook signs its first deal to pay News Corp to use its content in Australia</a></li>
<li><a href="https://www.gizmochina.com/2021/02/14/top-stories-from-last-week-mi-11-global-launch-first-look-at-the-mi-11-ultra-facebook-is-making-a-smartwatch-and-more/" target="_blank" rel="noopener noreferrer">Top stories from last week: Mi 11 global launch, first look at the Mi 11 Ultra, Facebook is making a smartwatch, and more</a></li>
</ul>
<p><iframe loading="lazy" title="OPPO Find X3 Pro Full Review: Not as powerful as expected" width="696" height="392" src="https://www.youtube.com/embed/ngyc3YNVWQI?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/04/05/500-million-facebook-users-phone-numbers-data-leaked/">Over 500 million Facebook users&#8217; phone numbers and personal data leaked</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple M1 chip found to be vulnerable to browser-based side-channel attack</title>
		<link>https://www.gizmochina.com/2021/03/12/apple-m1-vulnerable-javascript-free-attack/</link>
		
		<dc:creator><![CDATA[Jeet]]></dc:creator>
		<pubDate>Fri, 12 Mar 2021 08:14:57 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Apple M1]]></category>
		<category><![CDATA[Apple Silicon]]></category>
		<category><![CDATA[Chips]]></category>
		<category><![CDATA[Chipset]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=376773</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple m1 chip" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-696x391.png 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png 715w" sizes="(max-width: 300px) 100vw, 300px" /><p>Apple recently launched its first chipset under Apple Silicon &#8212; M1 and the company have already started transitioning from the Intel-based chips to its own ARM-based processors. While the user&#8217;s response has been pretty good, we keep hearing about issues facing the new M1-powered devices as time goes by. In the latest development, security researchers [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/03/12/apple-m1-vulnerable-javascript-free-attack/">Apple M1 chip found to be vulnerable to browser-based side-channel attack</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple m1 chip" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-696x391.png 696w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png 715w" sizes="(max-width: 300px) 100vw, 300px" /><p>Apple recently launched its first chipset under <a href="https://www.gizmochina.com/tag/apple-silicon">Apple Silicon</a> &#8212; M1 and the company have already started transitioning from the Intel-based chips to its own ARM-based processors. While the user&#8217;s response has been pretty good, we keep hearing about issues facing the new M1-powered devices as time goes by.</p>
<p>In the latest development, <a href="https://arxiv.org/abs/2103.04952v1">security researchers have discovered</a> a first browser side-channel attack that is JavaScript-free and it appears that the new Apple M1 chips may be vulnerable to the attack.</p>
<p><img loading="lazy" class="aligncenter wp-image-353316 size-full" src="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png?x44794" alt="Apple m1 chip" width="715" height="402" srcset="https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1.png 715w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-300x169.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/11/apple-m1-696x391.png 696w" sizes="(max-width: 715px) 100vw, 715px" /></p>
<p>Researchers at Cornell University started with the goal of exploring the effectiveness of disabling or restricting JavaScript for mitigating attacks. During the research, they created a new side-channel proof of concept in CSS and HTML which could open the door to &#8220;microarchitectural website fingerprinting attacks.&#8221; It works even if script execution is completely blocked on a browser.</p>
<p>The vulnerability allows attackers to eavesdrop on a user&#8217;s web activity by leveraging features in the target&#8217;s packet sequence. Not only can it bypass JavaScript but it also disregards privacy <a href="https://www.gizmochina.com/tag/technology">technologies</a> like VPNs or TOR.</p>
<p>The team tested the attack on Intel Core, <a href="https://www.gizmochina.com/tag/amd">AMD</a> Ryzen, Samsung Exynos, and Apple M1 chips and while almost all CPU architectures are susceptible to the attack, the researchers claim that Apple M1 and <a href="https://www.gizmochina.com/tag/samsung-exynos">Samsung Exynos</a> chips are more vulnerable to their exploits.</p>
<p>This is the second vulnerability found to affect Apple M1 chip that has surfaced in recent weeks. Last month, researchers discovered a mysterious <a href="https://www.gizmochina.com/2021/02/18/first-malware-for-apple-m1-chip-discovered/">malware strain called Silver Sparrow</a> that had the ability to run natively on Mac devices with M1 chips.</p>
<p><strong>RELATED: </strong></p>
<ul>
<li><a href="https://www.gizmochina.com/2021/03/10/qualcomm-next-gen-snapdragon-8cx-apple-m1-rival/">Qualcomm working on next-gen Snapdragon 8cx chipset to take on Apple M1</a></li>
<li><a href="https://www.gizmochina.com/2021/03/05/apple-m1-macbook-air-refurbished-listed-china-store/">Apple M1-based 2020 MacBook Air refurbished models listed on China Apple store</a></li>
<li><a href="https://www.gizmochina.com/2021/03/11/apple-officially-announces-iphone-12-assembly-india/">Apple officially announces it has commenced iPhone 12 assembly in India</a></li>
</ul>
<p><iframe loading="lazy" title="HUAWEI Matebook X Laptop Review: The most beautiful ultraportable laptop in 2020" width="696" height="392" src="https://www.youtube.com/embed/HELRDZpdqz4?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2021/03/12/apple-m1-vulnerable-javascript-free-attack/">Apple M1 chip found to be vulnerable to browser-based side-channel attack</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Vulnerabilities in Qualcomm chipset puts millions of Android phones at risk</title>
		<link>https://www.gizmochina.com/2020/08/18/qualcomm-snapdragon-achilles-vulnerability/</link>
		
		<dc:creator><![CDATA[Jeet]]></dc:creator>
		<pubDate>Tue, 18 Aug 2020 05:43:50 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Qualcomm]]></category>
		<category><![CDATA[Mobile Chipset]]></category>
		<category><![CDATA[Processor]]></category>
		<category><![CDATA[Qualcomm Snapdragon]]></category>
		<category><![CDATA[Smartphone Chipset]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=337514</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Qualcomm Snapdragon Processor" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon.jpg 750w" sizes="(max-width: 300px) 100vw, 300px" /><p>Researchers have found that Snapdragon series smartphone chipsets from Qualcomm, which is widely being used in Android devices, has over 400 instances of vulnerable code that puts millions of users at risk. Check Point, a cybersecurity firm has found that the DSP (Digital Signal Processor) used in Qualcomm Snapdragon chipset has the vulnerable code which [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/08/18/qualcomm-snapdragon-achilles-vulnerability/">Vulnerabilities in Qualcomm chipset puts millions of Android phones at risk</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Qualcomm Snapdragon Processor" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon.jpg 750w" sizes="(max-width: 300px) 100vw, 300px" /><p>Researchers have found that <a href="https://www.gizmochina.com/tag/snapdragon/">Snapdragon series</a> smartphone chipsets from Qualcomm, which is widely being used in Android devices, has over 400 instances of vulnerable code that puts millions of users at risk.</p>
<p>Check Point, a cybersecurity firm <a href="https://blog.checkpoint.com/2020/08/06/achilles-small-chip-big-peril/">has found</a> that the DSP (Digital Signal Processor) used in Qualcomm Snapdragon chipset has the vulnerable code which it is calling &#8220;Achilles&#8221; and is claimed to impact phones to be used as a spying tool.</p>
<p><img loading="lazy" class="aligncenter wp-image-263536 size-full" src="https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon.jpg?x44794" alt="Qualcomm Snapdragon Processor" width="750" height="500" srcset="https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon.jpg 750w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2019/07/snapdragon-630x420.jpg 630w" sizes="(max-width: 750px) 100vw, 750px" /></p>
<p>An app can bypass the usual security measures and can then access phone&#8217;s photos, videos, <a href="https://www.gizmochina.com/tag/gps">GPS</a>, and location data, that too without the owner knowing about it. The attacker can also lock the phone with all the data stored, rendering it useless. It can also be used to store unknown and unremovable malware on the device.</p>
<p>The research firm has said that it has notified Qualcomm about its findings, as well as government officials and affected vendors. Given that millions of <a href="https://www.gizmochina.com/tag/android">Android</a> devices are at risk, the company has not published the details about its findings.</p>
<p style="text-align: center"><strong><span style="color: #ff0000">EDITOR&#8217;S PICK:</span> </strong><a title="iQOO 5, iQOO 5 Pro launched with 120W fast charging, 120Hz curved display, and 50MP triple cameras" href="https://www.gizmochina.com/2020/08/17/iqoo-5-iqoo-5-pro-launched-with-120w-fast-charging-120hz-curved-display-and-50mp-triple-cameras/" rel="bookmark"><strong>iQOO 5, iQOO 5 Pro launched with 120W fast charging, 120Hz curved display, and 50MP triple cameras</strong></a></p>
<p>It is also being reported that Qualcomm has now fixed the issue but the affected devices can only be secured once the phone manufacturers start pushing the relevant updates and <a href="https://www.gizmochina.com/tag/security-patch">security patches</a> to the affected phones, which is likely to take time.</p>
<p>In a statement, Qualcomm said that it has worked hard to validate and fix the issues. It also added that the company has not found any evidence of the Achilles <a href="https://www.gizmochina.com/tag/vulnerability">vulnerability</a> being exploited in the wild.</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/08/17/us-reinforces-restrictions-on-huaweis-access-to-chips-and-other-tech/">United States reinforces restrictions put on Chinese giant Huawei’s access to chips and other technologies</a></strong></h6>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/08/18/qualcomm-snapdragon-achilles-vulnerability/">Vulnerabilities in Qualcomm chipset puts millions of Android phones at risk</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple Secure Enclave chip found to have &#8216;unpatchable&#8217; exploit</title>
		<link>https://www.gizmochina.com/2020/08/03/apple-secure-enclave-exploit/</link>
		
		<dc:creator><![CDATA[Jeet]]></dc:creator>
		<pubDate>Mon, 03 Aug 2020 06:12:49 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Chip]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Secure Enclave]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=335114</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo.jpg 944w" sizes="(max-width: 300px) 100vw, 300px" /><p>For the past few years, Apple started included the Secure Enclave chip on its devices as a way to encrypt and secure user data stored on the device. Now, a new exploit has allegedly been found for the chip, putting data of millions of users at risk. As per the reports, Chinese hackers from the [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/08/03/apple-secure-enclave-exploit/">Apple Secure Enclave chip found to have &#8216;unpatchable&#8217; exploit</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="Apple" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo-630x420.jpg 630w, https://www.gizmochina.com/wp-content/uploads/2020/04/apple-logo.jpg 944w" sizes="(max-width: 300px) 100vw, 300px" /><p>For the past few years, <a href="https://www.gizmochina.com/tag/apple">Apple</a> started included the Secure Enclave chip on its devices as a way to encrypt and secure user data stored on the device. Now, a new exploit has allegedly been found for the chip, putting data of millions of users at risk.</p>
<p><img loading="lazy" class="size-full wp-image-335117 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit.png?x44794" alt="Apple Secure Enclave Exploit" width="2436" height="1125" srcset="https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit.png 2436w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-300x139.png 300w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-768x355.png 768w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-1024x473.png 1024w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-696x321.png 696w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-1068x493.png 1068w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-909x420.png 909w, https://www.gizmochina.com/wp-content/uploads/2020/08/Apple-Secure-Enclave-Exploit-1920x887.png 1920w" sizes="(max-width: 2436px) 100vw, 2436px" /></p>
<p>As per the reports, Chinese hackers from the Pangu Team have found an &#8220;unpatchable&#8221; exploit on the Apple Secure Enclave chip that could break the encryption of the private keys stored on the device.</p>
<p>This is claimed to be unpatchable because the vulnerability is related to the hardware and not <a href="https://www.gizmochina.com/tag/software">software</a>, so there&#8217;s nothing Apple can do to fix this issue for the devices that have already been shipped. This also means that hackers need to have physical access to the device in order to do obtain data.</p>
<p>While there are no exact details available about the exploit, but the devices at risk include all the devices running Apple A7 chipset to <a href="https://www.gizmochina.com/2018/02/12/snapdragon-845-battles-snapdragon-835-exynos-8895-kirin-970-apple-a11-bionic/">A11 Bionic</a> chip.</p>
<blockquote class="twitter-tweet" data-width="550" data-dnt="true">
<p lang="en" dir="ltr">The Team Pangu has found an “unpatchable” vulnerability on the Secure Enclave Processor (SEP) chip in iPhones. <a href="https://t.co/9oJYu3k8M4">https://t.co/9oJYu3k8M4</a></p>
<p>&mdash; Jin Wook Kim (@wugeej) <a href="https://twitter.com/wugeej/status/1288284751057412097?ref_src=twsrc%5Etfw">July 29, 2020</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p style="text-align: center"><span style="color: #ff0000"><strong>EDITOR&#8217;S PICK: </strong></span><a title="Apple vendor is reportedly planning to shift iPhone production to India" href="https://www.gizmochina.com/2020/08/03/apple-vendor-iphone-production-india/" rel="bookmark"><strong>Apple vendor is reportedly planning to shift iPhone production from China to India</strong></a></p>
<p>Following devices come packed with Secure Enclave chip:</p>
<ul>
<li>iPhone 5s and later</li>
<li>iPad (5th gen) and later</li>
<li><a href="https://www.gizmochina.com/tag/ipad">iPad</a> Air (1st gen) and later</li>
<li>iPad mini 2 and later</li>
<li>iPad Pro</li>
<li>Mac computers with the T1 or T2 chip</li>
<li>Apple TV HD (4th gen) and later</li>
<li>Apple Watch Series 1 and later</li>
<li><a href="https://www.gizmochina.com/2017/06/06/apple-homepod-launched-new-smart-speaker-musicologist-built-reinvent-music-experience-home/">HomePod</a></li>
</ul>
<p>For those who are unaware, Secure Enclave is a security-related co-processor that Apple includes in almost all of its devices now as a way of providing an extra layer of security for the user data stored locally on the device.</p>
<p>The data on the device is encrypted with random private keys, which can only be accessed by the Secure Enclave. These keys are unique to the device and are never synchronized with iCloud. The chip also stores keys for passwords, the credit card for Apple Pay, and even biometric data for Touch ID and <a href="https://www.gizmochina.com/tag/face-id">Face ID</a>.</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/08/03/mobile-gaming-revenue-rise-q2-2020/">Mobile gaming revenue surges 27 percent in Q2 2020; generates $19.3 billion</a></strong></h6>
<p>&nbsp;</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/08/03/apple-secure-enclave-exploit/">Apple Secure Enclave chip found to have &#8216;unpatchable&#8217; exploit</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Apple iPhone&#8217;s Mail App suffers from a severe security flaw, Company declined to comment</title>
		<link>https://www.gizmochina.com/2020/04/23/apple-iphones-mail-app-suffers-from-a-severe-security-flaw-company-declined-to-comment/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 23 Apr 2020 09:58:00 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=318751</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr.jpg 640w" sizes="(max-width: 300px) 100vw, 300px" /><p>A new vulnerability might have just been found in Apple iPhones. Security researchers have claimed that the default iOS Mail app suffers from a severe security flaw and is vulnerable to attacks from hackers. According to a report from ZecOps, the vulnerability is already being exploited &#8220;in the wild&#8221; and that it is an advanced [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/04/23/apple-iphones-mail-app-suffers-from-a-severe-security-flaw-company-declined-to-comment/">Apple iPhone&#8217;s Mail App suffers from a severe security flaw, Company declined to comment</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr.jpg 640w" sizes="(max-width: 300px) 100vw, 300px" /><p>A new vulnerability might have just been found in <a href="https://www.gizmochina.com/tag/apple/" target="_blank" rel="noopener noreferrer">Apple</a> iPhones. Security researchers have claimed that the default iOS Mail app suffers from a severe security flaw and is vulnerable to attacks from hackers.</p>
<p>According to a report from ZecOps, the vulnerability is already being exploited &#8220;in the wild&#8221; and that it is an advanced threat that Apple is unaware of. The research agency believes that at least 6 high profile targets have been exploited so far, including a Japanese mobile carrier executive and other &#8220;individuals from a Fortune 500 company in North America.”</p>
<p><img loading="lazy" class="aligncenter wp-image-116923 size-full" src="https://www.gizmochina.com/wp-content/uploads/2017/02/apple-iphones.jpg?x44794" alt="apple india" width="1200" height="900" /></p>
<p>ZecOps have refrained from mentioning names stating privacy reasons but said that it was unable to obtain the malicious code since the emails were remotely deleted by hackers. The firm believes that the vulnerability is related to 2 zero-day iOS exploits that have existed in the Mail app since at least iOS 6, which was launched back in 2012.</p>
<h6 class="related"><strong>Editor&#8217;s Pick: <a href="https://www.gizmochina.com/2020/04/23/realme-x50m-5g-launched-with-120hz-display-sd765g-30w-charging-and-48mp-quad-cameras-for-1999-yuan-282/">Realme X50m 5G launched with 120Hz display, SD765G, 30W charging and 48MP quad cameras for 1,999 Yuan (~$282)</a></strong></h6>
<p>According to ZecOps, &#8220;the attack’s scope consists of sending a specially crafted email to a victim’s mailbox enabling it to trigger the vulnerability in the context of iOS MobileMail application on iOS 12 or mailed on iOS 13.” However, the method to reproduce this vulnerability has failed so far by various other researchers. This includes Jann Horn and Maddie Stone from Google&#8217;s Project Zero cybersecurity program.</p>
<blockquote class="twitter-tweet" data-width="550" data-dnt="true">
<p lang="en" dir="ltr"><a href="https://twitter.com/ZecOps?ref_src=twsrc%5Etfw">@ZecOps</a> your writeup says &quot;The suspicious events included strings commonly used by hackers (e.g. 414141…4141).&quot;, but that&#39;s also what it looks like when you just base64-encode nullbytes; and this is MIME parsing, so you&#39;re likely to see base64-encoded data</p>
<p>&mdash; Jann Horn (@tehjh) <a href="https://twitter.com/tehjh/status/1253010131283034114?ref_src=twsrc%5Etfw">April 22, 2020</a></p></blockquote>
<p><script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></p>
<p>Notably, Apple was reached out from Beijing News reported in China to verify the report from ZecOps, regarding the vulnerability the iOS mail app faces on iPhones. Unfortunately, Apple China declined to comment on the situation so we have no official confirmation. Other researchers are currently asking ZecOps to provide more details on how to recreate the vulnerability to actually prove the security flaw&#8217;s existence.</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/04/23/huawei-to-soon-launch-headphones-and-smart-eyewear-powered-by-the-kirin-a1-chip-report/">Huawei to soon launch headphones and smart eyewear powered by the Kirin A1 chip: Report</a></strong></h6>
<p>&nbsp;</p>
<p>(Via:<a href="https://www.theverge.com/2020/4/22/21231454/apple-iphone-zero-day-exploit-security-flaw-mail-app-ios-zec-ops" target="_blank" rel="noopener noreferrer">1</a>,<a href="https://tech.sina.com.cn/it/2020-04-23/doc-iircuyvh9404703.shtml?cre=tianyi&amp;mod=pctech&amp;loc=2&amp;r=25&amp;rfunc=96&amp;tj=none&amp;tr=25" target="_blank" rel="noopener noreferrer">2</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/04/23/apple-iphones-mail-app-suffers-from-a-severe-security-flaw-company-declined-to-comment/">Apple iPhone&#8217;s Mail App suffers from a severe security flaw, Company declined to comment</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Researchers warn against new Cybersecurity threats during Coronavirus pandemic</title>
		<link>https://www.gizmochina.com/2020/04/22/researchers-warn-against-new-cybersecurity-threats-during-coronavirus-pandemic/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Wed, 22 Apr 2020 10:17:06 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[coronavirus]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=318472</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w" sizes="(max-width: 300px) 100vw, 300px" /><p>The world is gripped by the recent Coronavirus pandemic that has affected virtually every country. However, the threats from the virus may not be limited just there as researchers warn against increasing cybersecurity threats amidst the ongoing crisis. As various governments are enforcing lockdowns, work is quickly shifting towards the digital and online realms. But [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/04/22/researchers-warn-against-new-cybersecurity-threats-during-coronavirus-pandemic/">Researchers warn against new Cybersecurity threats during Coronavirus pandemic</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w" sizes="(max-width: 300px) 100vw, 300px" /><p>The world is gripped by the recent <a href="https://www.gizmochina.com/tag/coronavirus/" target="_blank" rel="noopener noreferrer">Coronavirus</a> pandemic that has affected virtually every country. However, the threats from the virus may not be limited just there as researchers warn against increasing cybersecurity threats amidst the ongoing crisis.</p>
<p>As various governments are enforcing lockdowns, work is quickly shifting towards the digital and online realms. But with this increase in traffic online, apart from just pressures on ISPs and telecom operators, it seems that risk online has increased as well. At the moment, crucial fields like education are under transition, but researchers have warned against potential risks.</p>
<p><img loading="lazy" class="size-full wp-image-297545 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2019/12/424a9c7cc05d238ae1022307c7fb3c12-1.jpg?x44794" alt="" width="945" height="475" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/424a9c7cc05d238ae1022307c7fb3c12-1.jpg 945w, https://www.gizmochina.com/wp-content/uploads/2019/12/424a9c7cc05d238ae1022307c7fb3c12-1-300x151.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/424a9c7cc05d238ae1022307c7fb3c12-1-768x386.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2019/12/424a9c7cc05d238ae1022307c7fb3c12-1-696x350.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2019/12/424a9c7cc05d238ae1022307c7fb3c12-1-836x420.jpg 836w" sizes="(max-width: 945px) 100vw, 945px" /></p>
<p>According to CNCERT (National Computer Network Emergency Response Technical Team and Coordination Center of China), “More businesses in traditional industries are accelerating their digital transformation by using remote-working technologies to ensure business continuity, resulting in a spike in cyber threats arising from data leakage, phishing scams, ransomware, and internet frauds.”</p>
<h6 class="related"><strong>Editor&#8217;s Pick: <a href="https://www.gizmochina.com/2020/04/22/huawei-smartphones-sold-over-450000-units-in-china-in-march-the-p40-series-arrives-with-hms-ceo/">Huawei smartphones sold over 450,000 units in China in March, the P40 series arrives with HMS: CEO</a></strong></h6>
<p>The firm is a Chinese government cybersecurity agency that believes that remote working apps, online medical consultations, and e-learning systems could potentially harbor various risks, like hackers that could exploit vulnerabilities. Examples of this occurring is already here as online educational platforms have been suffering from DDoS attacks (Distributed denial-of-service) ever since the COVID-19 lockdowns began. This even goes as far back in January 2020.</p>
<p>These DDoS attacks essentially crash the server since it bombards the system with a massive number of requests. Similarly, phishing attacks are another attempt through which hackers try and gain access to sensitive data. These may be in the form of usernames, passwords, or even credit card details and can be made through communications online like fraud emails.</p>
<p><img loading="lazy" class="size-full wp-image-297549 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg?x44794" alt="" width="620" height="414" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w, https://www.gizmochina.com/wp-content/uploads/2019/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w" sizes="(max-width: 620px) 100vw, 620px" /></p>
<p>An example of an organized hacker group is DarkHotel. This East Asia based group has already attempted to break into to the World Health Organization&#8217;s (WHO) internal system. Furthermore, they are also responsible for coordinated cyber espionage campaigns against various Chinese agencies and their diplomatic mission through VPNs (virtual private network).</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/04/22/huawei-sees-low-revenue-growth-in-first-quarter-coronavirus-and-us-pressures-hit-hard/">Huawei sees low Revenue Growth in first quarter, Coronavirus and US Sanctions hit hard</a></strong></h6>
<p>&nbsp;</p>
<p>(<a href="https://www.scmp.com/tech/enterprises/article/3080876/new-cybersecurity-threats-emerging-amid-coronavirus-pandemic" target="_blank" rel="noopener noreferrer">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/04/22/researchers-warn-against-new-cybersecurity-threats-during-coronavirus-pandemic/">Researchers warn against new Cybersecurity threats during Coronavirus pandemic</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>More than a Billion iOS and Android smartphone are vulnerable by a flaw in the Wi-Fi Chip</title>
		<link>https://www.gizmochina.com/2020/02/27/more-than-a-billion-ios-and-android-smartphone-are-vulnerable-by-a-flaw-in-the-wi-fi-chip/</link>
		
		<dc:creator><![CDATA[Sean]]></dc:creator>
		<pubDate>Thu, 27 Feb 2020 12:57:41 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Samsung]]></category>
		<category><![CDATA[Top Stories]]></category>
		<category><![CDATA[Android Vulnerability]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=307439</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr.jpg 640w" sizes="(max-width: 300px) 100vw, 300px" /><p>A major flaw has just been discovered in the Wi-Fi chips of a couple of smartphone models that potentially affect over a billion people. Reportedly, attackers are now capable of decrypting data that was sent to these handset models, even if the messages were encrypted in the first place. The flaw in question has been [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/02/27/more-than-a-billion-ios-and-android-smartphone-are-vulnerable-by-a-flaw-in-the-wi-fi-chip/">More than a Billion iOS and Android smartphone are vulnerable by a flaw in the Wi-Fi Chip</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr.jpg 640w" sizes="(max-width: 300px) 100vw, 300px" /><p>A major flaw has just been discovered in the Wi-Fi chips of a couple of smartphone models that potentially affect over a billion people. Reportedly, attackers are now capable of decrypting data that was sent to these handset models, even if the messages were encrypted in the first place.</p>
<p>The flaw in question has been traced back to Wi-Fi chips that have been manufactured by a particular company called Cypress Semiconductor and Broadcom. As the name suggests, the company deals with Wi-Fi components and Cypress had initially acquired Broadcom&#8217;s Wi-Fi operations back in 2016. The recently uncovered Wi-Fi flaw affects both the WPA2-Personal and WPA2-Enterprise protocols on the affected smartphones.</p>
<p><figure id="attachment_297116" aria-describedby="caption-attachment-297116" style="width: 770px" class="wp-caption aligncenter"><img loading="lazy" class="wp-image-297116 size-full" src="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand.jpg?x44794" alt="" width="770" height="578" srcset="https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand.jpg 770w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand-300x225.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand-768x576.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand-80x60.jpg 80w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand-265x198.jpg 265w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand-696x522.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2019/12/iphone-xr-in-hand-560x420.jpg 560w" sizes="(max-width: 770px) 100vw, 770px" /><figcaption id="caption-attachment-297116" class="wp-caption-text">Apple iPhone XR</figcaption></figure></p>
<p>The list of devices that are affected is found to be in both iPhones and Android smartphones. Furthermore, they are also found to be affecting certain models of <a href="https://www.gizmochina.com/tag/ipad/" target="_blank" rel="noopener noreferrer">iPad</a> from <a href="https://www.gizmochina.com/brand/apple/" target="_blank" rel="noopener noreferrer">Apple</a>, <a href="https://www.gizmochina.com/tag/amazon-echo/" target="_blank" rel="noopener noreferrer">Amazon Echo</a>, <a href="https://www.gizmochina.com/tag/kindle/" target="_blank" rel="noopener noreferrer">Kindle</a> readers, and Wi-Fi routers manufactured by <a href="https://www.gizmochina.com/brand/asus/" target="_blank" rel="noopener noreferrer">Asus </a>and <a href="https://www.gizmochina.com/brand/huawei/" target="_blank" rel="noopener noreferrer">Huawei</a>. The vulnerability was first uncovered by a Slovakian security firm named Eset, which has also dubbed it as KrØØk when reporting it earlier today (27th February 2020).</p>
<h6 class="related"><strong>Editor&#8217;s Pick: <a href="https://www.gizmochina.com/2020/02/27/patent-reveals-samsung-wants-to-reimagine-how-you-close-minimize-apps-on-your-smartphone/">Patent reveals Samsung wants to Reimagine how you close, minimize apps on your smartphone</a></strong></h6>
<p>As of right now, the manufacturers whose smartphones are affected have already started issuing patches to fix the issue, but it remains to be seen regarding the damage already done. Another difficulty being that the user might not read the crucial patch notes, so if your smartphones are one of the affected devices in the list down below, check for any pending software update and upgrade immediately.</p>
<ul>
<li><a href="https://www.gizmochina.com/tag/amazon-echo-2nd-gen/" target="_blank" rel="noopener noreferrer">Amazon Echo 2nd gen</a></li>
<li>Amazon Kindle 8th gen</li>
<li><a href="https://www.gizmochina.com/tag/apple-ipad-mini-2/" target="_blank" rel="noopener noreferrer">Apple iPad mini 2</a></li>
<li><a href="https://www.gizmochina.com/tag/apple-iphone-6/" target="_blank" rel="noopener noreferrer">Apple iPhone 6</a></li>
<li><a href="https://www.gizmochina.com/product/apple-iphone-6s/" target="_blank" rel="noopener noreferrer">Apple iPhone 6S</a></li>
<li><a href="https://www.gizmochina.com/tag/iphone-8/" target="_blank" rel="noopener noreferrer">Apple iPhone 8</a></li>
<li><a href="https://www.gizmochina.com/product/apple-iphone-xr/" target="_blank" rel="noopener noreferrer">Apple iPhone XR</a></li>
<li><a href="https://www.gizmochina.com/tag/macbook/" target="_blank" rel="noopener noreferrer">Apple MacBook</a></li>
<li><a href="https://www.gizmochina.com/tag/apple-ipad-air/" target="_blank" rel="noopener noreferrer">Apple iPad Air</a></li>
<li><a href="https://www.gizmochina.com/tag/google-nexus-5/" target="_blank" rel="noopener noreferrer">Google Nexus 5</a></li>
<li><a href="https://www.gizmochina.com/tag/google-nexus-6/" target="_blank" rel="noopener noreferrer">Google Nexus 6</a></li>
<li><a href="https://www.gizmochina.com/tag/huawei-nexus-6p/" target="_blank" rel="noopener noreferrer">Google Nexus 6P</a></li>
<li><a href="https://www.gizmochina.com/tag/waveshare-raspberry-pi-3-model-b-development-kit-type-g/" target="_blank" rel="noopener noreferrer">Raspberry Pi 3</a></li>
<li><a href="https://www.gizmochina.com/tag/samsung-galaxy-s4/" target="_blank" rel="noopener noreferrer">Samsung Galaxy S4</a></li>
<li><a href="https://www.gizmochina.com/product/samsung-galaxy-s8-g950k/" target="_blank" rel="noopener noreferrer">Samsung Galaxy S8</a></li>
<li><a href="https://www.gizmochina.com/tag/redmi-3s/" target="_blank" rel="noopener noreferrer">Xiaomi Redmi 3S</a></li>
</ul>
<p><figure id="attachment_157343" aria-describedby="caption-attachment-157343" style="width: 1483px" class="wp-caption aligncenter"><img loading="lazy" class="wp-image-157343 size-full" src="https://www.gizmochina.com/wp-content/uploads/2017/11/Galaxy-S8-Burgundy-Red-2.png?x44794" alt="Galaxy S8 Burgundy Red" width="1483" height="866" srcset="https://www.gizmochina.com/wp-content/uploads/2017/11/Galaxy-S8-Burgundy-Red-2.png 1483w, https://www.gizmochina.com/wp-content/uploads/2017/11/Galaxy-S8-Burgundy-Red-2-300x175.png 300w, https://www.gizmochina.com/wp-content/uploads/2017/11/Galaxy-S8-Burgundy-Red-2-768x448.png 768w, https://www.gizmochina.com/wp-content/uploads/2017/11/Galaxy-S8-Burgundy-Red-2-1024x598.png 1024w" sizes="(max-width: 1483px) 100vw, 1483px" /><figcaption id="caption-attachment-157343" class="wp-caption-text">Samsung Galaxy S8 Burgundy Red Edition</figcaption></figure></p>
<p>Unfortunately, Eset stated that it has yet to test a lot of smartphones from other OEMs and there is a great chance of the vulnerability being more widespread. Many companies have yet to respond to the issue but so far, the above mentioned handset models are confirmed to have the issue. Similarly, the affected routers would also require the installation of the latest firmware with the required security patches to be secured.</p>
<h6 class="related"><strong>UP NEXT: <a href="https://www.gizmochina.com/2020/02/27/huawei-opens-a-brand-new-retail-store-in-barcelona-right-in-front-of-apples-store/">Huawei opens a brand new retail store in Barcelona, right in front of Apple’s store</a></strong></h6>
<p>&nbsp;</p>
<p>(<a href="https://bit.ly/2I6eM4B" target="_blank" rel="noopener noreferrer">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2020/02/27/more-than-a-billion-ios-and-android-smartphone-are-vulnerable-by-a-flaw-in-the-wi-fi-chip/">More than a Billion iOS and Android smartphone are vulnerable by a flaw in the Wi-Fi Chip</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AirDrop vulnerability reveals phone number and passwords to third parties</title>
		<link>https://www.gizmochina.com/2019/08/02/airdrop-vulnerability-leaks-phone-number-passwords/</link>
		
		<dc:creator><![CDATA[Jeet]]></dc:creator>
		<pubDate>Fri, 02 Aug 2019 08:19:58 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[AirDrop]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=267848</guid>

					<description><![CDATA[<img width="300" height="207" src="https://www.gizmochina.com/wp-content/uploads/2018/01/iphone-6s-plus-home-screen-hero-300x207.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="iphone 6s plus" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/01/iphone-6s-plus-home-screen-hero-300x207.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/01/iphone-6s-plus-home-screen-hero.jpg 700w" sizes="(max-width: 300px) 100vw, 300px" /><p>A new security flaw has been discovered in Apple&#8216;s AirDrop feature which can let anyone with the computer and right software access some critical information, including phone numbers and Wi-Fi passwords. A report from Hexway claims that users just need to have Bluetooth turned on the broadcast to fall prey to this vulnerability. It says [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2019/08/02/airdrop-vulnerability-leaks-phone-number-passwords/">AirDrop vulnerability reveals phone number and passwords to third parties</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="207" src="https://www.gizmochina.com/wp-content/uploads/2018/01/iphone-6s-plus-home-screen-hero-300x207.jpg?x44794" class="webfeedsFeaturedVisual wp-post-image" alt="iphone 6s plus" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2018/01/iphone-6s-plus-home-screen-hero-300x207.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2018/01/iphone-6s-plus-home-screen-hero.jpg 700w" sizes="(max-width: 300px) 100vw, 300px" /><p>A new security flaw has been discovered in <a href="https://www.gizmochina.com/tag/apple">Apple</a>&#8216;s AirDrop feature which can let anyone with the computer and right software access some critical information, including phone numbers and Wi-Fi passwords.</p>
<p>A report from <em>Hexway</em> claims that users just need to have Bluetooth turned on the broadcast to fall prey to this vulnerability. It says that &#8220;simply having Bluetooth turned on broadcasts a host of device details, including its name, whether it&#8217;s in use if Wi-Fi is turned on, the OS version it&#8217;s running, and information about the battery.&#8221;</p>
<p><img loading="lazy" class="size-full wp-image-267851 aligncenter" src="https://www.gizmochina.com/wp-content/uploads/2019/08/airdrop.jpg?x44794" alt="Apple AirDrop" width="830" height="400" srcset="https://www.gizmochina.com/wp-content/uploads/2019/08/airdrop.jpg 830w, https://www.gizmochina.com/wp-content/uploads/2019/08/airdrop-300x145.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2019/08/airdrop-768x370.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2019/08/airdrop-696x335.jpg 696w" sizes="(max-width: 830px) 100vw, 830px" /></p>
<p>It also adds that using AirDrop or Wi-Fi password sharing broadcasts a partial cryptographic hash which can easily be converted into a phone number. In the case of a Mac, a static MAC address, which can be used as a unique identifier—is also sent in Bluetooth Low Energy packets.</p>
<p><iframe loading="lazy" width="696" height="392" src="https://www.youtube.com/embed/QkGCP2mfbJ8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe></p>
<p>Hexway has also shared a video demonstrating the vulnerability in action. It&#8217;s a fairly simple process for malicious third parties. With a proof-of-concept trial, the report was able to gather dozens of iPhones and Apple Watches within range. All that was needed for this was a computer and sniffer dongle.</p>
<p><div class="su-note"  style="border-color:#e5e5e5;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><div class="su-note-inner su-u-clearfix su-u-trim" style="background-color:#ffffff;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;"><span style="color: #ff0000"><strong>Editor&#8217;s Pick: </strong></span><a title="Huawei Mate 30 Pro to reportedly come with AirGlass and SuperSensing Camera" href="https://www.gizmochina.com/2019/08/02/huawei-mate-30-pro-airglass-supersensing-features/" rel="bookmark"><strong>Huawei Mate 30 Pro flagship smartphone to reportedly come with AirGlass screen guard and SuperSensing Camera</strong></a></div></div></p>
<p>Hexway is calling this issue more of a &#8220;behavior&#8221; than a &#8220;vulnerability&#8221; as it is baked into <a href="https://www.gizmochina.com/tag/ios">iOS</a>. Currently, the only security measure you can take against this flaw is turning off Bluetooth entirely, which may not be an appropriate solution for everyone.</p>
<p>While Apple may find more secure ways to protect data like phone numbers when it’s over the air between devices, eliminating its use entirely could be quite a challenge since those details are needed for devices to identify themselves to each other when using AirDrop.</p>
<p>(<a href="https://hexway.io/blog/apple-bleee/">Source</a>)</p>
<h4 style="text-align: center"><strong><span style="color: #ff0000">Up Next:</span> <a href="https://www.gizmochina.com/2019/08/02/htc-may-return-to-the-indian-market-this-month/">HTC will reportedly return to the Indian smartphone market later this month</a></strong></h4>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2019/08/02/airdrop-vulnerability-leaks-phone-number-passwords/">AirDrop vulnerability reveals phone number and passwords to third parties</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 176/341 objects using Redis
Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudflare
Database Caching 15/47 queries in 0.021 seconds using Redis
Fragment Caching 2/3 fragments using Redis

Served from: www.gizmochina.com @ 2026-06-12 13:54:19 by W3 Total Cache
-->