Vulnerabilities / Threats

1/28/2019
09:30 PM
50%
50%

Turn Off FaceTime in Apple iOS Now, Experts Warn

Newly found bug reportedly allows callers to spy on you - even if you don't pick up.

[This is a developing story -- more updates to come]

Security experts are warning Apple iOS users to immediately disable FaceTime on their devices after word began to spread today about a newly discovered bug that allows anyone to call you via the app and access your audio and video even if you don't answer the call.

Apple told BuzzFeed that the company was "aware of this issue and we have identified a fix that will be released in a software update later this week."

A video of how to FaceTime people and listen in or see them via their cameras spread via social media today, and the blog 9to5Mac later posted the actual steps involved:

  • "Start a FaceTime Video call with an iPhone contact.
  • Whilst the call is dialling, swipe up from the bottom of the screen and tap Add Person.Add your own phone number in the Add Person screen.
  • You will then start a group FaceTime call including yourself and the audio of the person you originally called, even if they haven’t accepted the call yet."

The best protection for now is to disable or turn off FaceTime, experts say.

Read more here and here

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jason899889
50%
50%
jason899889,
User Rank: Apprentice
4/21/2019 | 11:17:40 AM
Pending Review
This comment is waiting for review by our moderators.
MelBrandle
50%
50%
MelBrandle,
User Rank: Apprentice
2/26/2019 | 2:46:28 AM
So.. What then?
While I'm sure that this threat is legitimate in terms of allowing some strange person to access your phone and other tech devices, I can't fathom what kind of danger having access to sound and audio could make. I mean, how could this cause a disruption? Perhaps I'm not thinking like a terrorist, but I think that there wouldn't be much impale even if someone were to commandeer those functions of my mobile device?
ThomasMaloney
50%
50%
ThomasMaloney,
User Rank: Apprentice
2/14/2019 | 1:03:12 AM
Another level of hack
This is a huge breakthrough in the realm of security hacks so far. I have just disabled my FaceTime function and even pasted a small sticker to cover the front camera of my phone. I know I am not someone who anyone would want to even hack, but that level of paranoia is just erupting as we speak.
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11378
PUBLISHED: 2019-04-20
An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. It is possible for users to read arbitrary files and (potentially) access the supporting database, delete arbitrary files, access user passwords, or run arbitrary code.
CVE-2019-11372
PUBLISHED: 2019-04-20
An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11373
PUBLISHED: 2019-04-20
An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
CVE-2019-11374
PUBLISHED: 2019-04-20
74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.
CVE-2019-11375
PUBLISHED: 2019-04-20
Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI.