UAE Authority Raise Alarm Over Security Flaws for Apple, Android users
A cyber security threat that may have an effect on users of Apple and Android has been alerted to by the UAE Cyber Security Council.
UAE Cyber Security Council's Advisory
The advisory highlights that Apple has taken swift action to address a critical security vulnerability by issuing an emergency update. This update specifically targets and resolves the security issues identified with the following Common Vulnerabilities and Exposures (CVE) identifiers: CVE-2023-41064, CVE-2023-41061, and CVE-2023-35674. These vulnerabilities posed a substantial risk to the security and privacy of Apple device users.
The UAE Cyber Security Council advises users to promptly install the latest updates provided by both Apple and Android to mitigate the security risk posed by these vulnerabilities. The identified flaws have the potential to enable unauthorized access to sensitive information and grant full control of the affected devices.
The cyber security watchdog Citizen Lab investigated and discovered spyware linked to the NSO cyber intelligence firm. This spyware was found to exploit a very recently identified Apple device vulnerability.
Citizen Lab's Spyware Discovery
In one instance, Citizen Lab identified the use of this flaw to infect an Apple device owned by an employee of a Washington-based civil society group. Apple subsequently confirmed to Citizen Lab that utilizing the high-security feature known as "Lockdown Mode" on Apple devices effectively blocks this specific attack.
iPhone Vulnerability Mitigated:
The security flaw allowed for the compromise of iPhones running the latest iOS version (16.6) without any interaction required from the device's owner. Fortunately, the new update from Apple addresses and rectifies this vulnerability, enhancing the security of affected devices.
The warning from the UAE Cyber Security Council serves as a reminder of the importance of promptly updating devices to protect against potential security threats and vulnerabilities. Cybersecurity remains a critical concern in the digital age, and staying vigilant and proactive is crucial in safeguarding sensitive information and personal devices from malicious actors.