Lucene search

K
threatpostElizabeth MontalbanoTHREATPOST:EAC6870040C1AF7181CB7787FE315EDD
HistorySep 25, 2019 - 11:19 a.m.

Apple to Patch Bug Granting Full Access to 3rd-Party Keyboards

2019-09-2511:19:11
Elizabeth Montalbano
threatpost.com
101

0.002 Low

EPSS

Percentile

61.9%

Apple is readying a fix for a bug that could grant full access to third-party keyboards for its mobile devices, including iPhone and iPad.

The company posted an alert on its support page about an issue with iOS 13 and iPadOS that affects third-party keyboards users may have installed for the iPhone, iPad or iPod touch.

ā€œApple has discovered a bug in iOS 13 and iPadOS that can result in keyboard extensions being granted full access even if you havenā€™t approved this access,ā€ the company wrote in the alert. ā€œThe issue will be fixed soon in an upcoming software update.ā€
Third-party keyboards have two modes in which they can run in iOSā€“entirely standalone, without access to external services, or with full access to provide additional features through network access, according to Apple.

The bug does not impact Appleā€™s built-in keyboards, nor does it impact third-party keyboards that donā€™t make use of full access, the company said.

While users wait for the patch, Apple advised users to check their third-party keyboard in Settings on their devices.

The bug is not the first found in the most recent release of iOS, the system that runs Appleā€™s ubiquitously popular mobile devices.

In July, Jose Rodriguez, an Apple enthusiast based in Spain, alerted users to an iPhone lock screen bypass in iOS 13ā€”which at that point was in pre-release versionsā€“that could enable an attacker to access victimsā€™ address books. Data that could fall prey to unauthorized access included their contactsā€™ names, email addresses, phone numbers, mailing addresses and more, he said. Rodriguez also had previously discovered other security flaws in iPhones.

The discovery of vulnerabilities in the early days of the latest iOS releaseā€”which just came out on Thursdayā€“have led some to criticize Apple for what appears to be inattention to security in the latest version of its mobile OS.

ā€œSo thereā€™s a lock screen exploit in iOS 13, a keyboard access bug, and what else?ā€ Tweeted Tom Warren, senior editor at U.K.-based science and culture website The Verge. ā€œApple focused on quality with iOS 12, and then totally dropped the ball with iOS 13.ā€

Users also are questioning Appleā€™s rather slow pace at fixing bugs in the new OS. Though Rodriguez told the company about the lock-screen bug in July, it wasnā€™t patched until last week. Similarly, Apple did not provide a timeframe for when the latest keyboard bug would be patched, referring only to an upcoming update.

ā€œI mean, at least the screenshot bug Iā€™ve had since before last year is finally fixed,ā€ Tweeted freelance reporter Timothy J. Seppala in response to Warrenā€™s Twitter comment about the bug fix. Warren sarcastically replied, ā€œProgress.ā€

Interested in the role of artificial intelligence in cybersecurity, for both offense and defense? Donā€™t miss our freeThreatpost webinar, AI and Cybersecurity: Tools, Strategy and Advice, with senior editor Tara Seals and a panel of experts.Click here to register.

0.002 Low

EPSS

Percentile

61.9%

Related for THREATPOST:EAC6870040C1AF7181CB7787FE315EDD