4.9 • 696 Ratings
🗓️ 23 April 2020
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, April 23rd, 2020 edition of the Sansonet Stormsanders Stormcast. My name is Johannes Ulrich. |
0:10.0 | And then I'm recording from Jacksonville, Florida. |
0:14.0 | Well, we got some bad news for iOS users today. Israeli security company SecOps disclosed two vulnerabilities in iOS's |
0:24.3 | mail software that can trigger code execution. To make things worse, not only is there |
0:31.5 | no official patch for these vulnerabilities, there are also already some attacks going on that take advantage of |
0:40.4 | these vulnerabilities. |
0:42.6 | SecOps reports that they have seen several attacks in the wild, now targeted attacks, |
0:47.8 | so a lot of details have not been disclosed until today. |
0:53.1 | However, the blog post that SecOps published has an awful lot of detail about the vulnerability |
0:59.3 | that should make exploitation possible. |
1:04.1 | A couple of things here to sort of put this a little bit in perspective. |
1:06.9 | So first of all, this could be used to execute code within mail. |
1:11.6 | Now, iOS does isolate its different applications pretty well, |
1:16.8 | so this vulnerability by itself could not necessarily cause harm to the operating systems |
1:24.0 | or device or sort of any persistent damage without any additional vulnerabilities, |
1:30.1 | for example, approach escalation or sandbox escape or other kernel issues within iOS. So by itself, |
1:38.1 | these vulnerabilities aren't quite as bad as it may sound due to some of the other mitigation methods that iOS deploys. |
1:47.4 | There is, I say, no official patch. |
1:50.6 | Now, there is a patched version of iOS, and that's the current beta version of iOS. |
1:57.6 | So it hasn't been officially released yet, and of course, Apple typically doesn't pre-announce |
2:03.7 | their releases, but look out for it, certainly something that you want to apply quickly once |
2:10.8 | it's released. It affects iOS 13 as well as iOS 12. Now, the basic vulnerability has been present since iOS 6. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.