{"id":261927,"date":"2021-05-29T00:17:09","date_gmt":"2021-05-28T21:17:09","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/despite-fix-apple-has-yet-to-address-webkit-security-bug-affecting-iphone-and-macos\/"},"modified":"2021-05-29T00:17:09","modified_gmt":"2021-05-28T21:17:09","slug":"despite-fix-apple-has-yet-to-address-webkit-security-bug-affecting-iphone-and-macos","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/despite-fix-apple-has-yet-to-address-webkit-security-bug-affecting-iphone-and-macos\/","title":{"rendered":"#Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS"},"content":{"rendered":"<p>&#8220;<strong>#Despite fix, <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le has yet to address WebKit security bug affecting iPhone and MacOS<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2021\/despite-fix-apple-has.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/2021\/despite-fix-apple-has.jpg\" data-sub-html=\"Apple logo. Credit: Unsplash.com\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2021\/despite-fix-apple-has.jpg\" alt=\"Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS\" title=\"Apple logo. Credit: Unsplash.com\" width=\"800\" height=\"530\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Apple logo. Credit: Unsplash.com<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>While a fix emerged three weeks ago for the WebKit security bug affecting Apple products such as iPhone and Mac, Apple has yet to implement the fix. Researchers at the security firm Theori have found that WebKit mainly causes Safari to crash. However, following a re-check after the supplied fix, they discovered that the bug still remains on both iOS and MacOS.<\/p>\n<p>                                                                                &#8220;Patch-gapping&#8221; is the term for the time period between when a fix becomes available and the application of that fix to affected systems and products. In this case, Theori cautions Apple about waiting too long to make use of the fix for WebKit, lest attackers have more time and opportunity to compromise impacted systems. <\/p>\n<p>This vulnerability arose from WebKit which is a confusion bug taking advantage of AudioWorklet, the interface allowing developers to alter, control, render and play audio with the lowest possible latency. Unfortunately, attackers can exploit the WebKit bug to remotely execute evil code on affected devices. <\/p>\n<p>That said, attackers using WebKit would still have to circumvent Pointer Authentication Codes (PAC), an exploit mitigation system wherein users must input the correct cryptographic signature before code can be rendered in memory. That means that in the absence of either this signature or some kind of a bypass, attackers will fortunately not be able to run their malicious code.<\/p>\n<p>Researchers have confirmed that this exploit builds arbitrary read\/write primitives which attackers could use to build a chain of further exploits. Moreover, they stated that PAC bypass methods count as a distinct issue that should be disclosed separately. <\/p>\n<p>Thus far, WebKit has appeared in six of the eight Apple exploits already uncovered in 2021 alone.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Apple reveals two iOS zero-day vulnerabilities that allow attackers to access fully patched devices\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.theori.io\/research\/webkit-type-confusion\/\">blog.theori.io\/research\/webkit-type-confusion\/<\/a><\/p><\/div>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2021 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/sciencee\/\" data-internallinksmanager029f6b8e52c=\"5\" title=\"Science\" target=\"_blank\" rel=\"noopener\">Science<\/a> X Network<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS (2021, May 28)<br \/>\n                                                 retrieved 28 May 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-05-apple-webkit-bug-affecting-iphone.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-05-apple-webkit-bug-affecting-iphone.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Despite fix, Apple has yet to address WebKit security bug affecting iPhone and MacOS&#8221; Apple logo. Credit: Unsplash.com While a fix emerged three weeks ago for the WebKit security bug affecting Apple products such as iPhone and Mac, Apple has yet to implement the fix. Researchers at the security firm Theori have found that WebKit&#8230;<\/p>\n","protected":false},"author":1,"featured_media":261928,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/2021\/despite-fix-apple-has.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-261927","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/261927","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=261927"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/261927\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/261928"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=261927"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=261927"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=261927"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}