Positive Technologies specialists discovered vulnerabilities in Google and Apple operating systems, which allowed the companies to fix 11 security problems. TASS was informed about this by the company's press service. Two vulnerabilities in Android and Google Pixel received a high degree of danger and were closed with September updates.

The first problem in Android allowed an attacker, through a specially prepared NFC tag, to download, install, and launch an application without owner confirmation. The second allowed an already installed application to change the smartphone's network settings without additional permissions: connect to a specified Wi-Fi network, install a certificate, or change proxy parameters. Both were closed in September patches.

Nine vulnerabilities related to privilege escalation, privacy, and data protection were found in the Apple ecosystem. One in macOS allowed a malicious application to gain maximum system privileges. Others provided access to protected information, and in one scenario, allowed the deletion of access keys without user confirmation. Another was found in the OS kernel: it could lead to device failure or kernel memory corruption.

For users, this means the need to install the latest security updates. The NFC tag vulnerability is particularly dangerous because it does not require active actions from the victim – it is enough to bring the phone close to the tag. Apple and Google have already released patches, but devices that have not received the update remain at risk.

Read more on the topic:

Comments

правилами