top of page
blogbanner-thinstripback-compressor_edited.jpg
Original-LogoOnly-Square-SMLL-Pixel-Tran
  • linkedin
  • twitter
  • Instagram
  • YouTube
  • facebook

Written by Michael Plis. Your go-to source for smart technology & cybersecurity insights for small business. 

Writer's pictureMichael Plis

Revealed: Xcode Apple vulnerabilities

Updated: May 16


This alert covers the Xcode Apple vulnerabilities reported in 2019.


Xcode Apple vulnerabilities overview


Multiple vulnerabilities have been discovered in Xcode, tvOS (Apple TV), Safari (browser), iOS (iPhones), iPadOS (iPads), watchOS, Mac OS: Mojave, High Sierra and Sierra. The most severe of these vulnerabilities could allow for hacker to run malicious code.

  • Xcode is an integrated development environment for MacOS

  • tvOS is an operating system for the fourth-generation Apple TV digital media player.

  • Safari is a web browser available for OS X.

  • iOS is a mobile operating system for mobile devices, including the iPhone, iPad, and iPod touch.

  • iPadOS is the successor to iOS 12 and is a mobile operating system for iPads

  • watchOS is the mobile operating system for the Apple Watch and is based on the iOS operating system.

  • Mojave OS is a desktop and server operating system for Macintosh computers.

  • High Sierra OS is a desktop and server operating system for Macintosh computers.

  • Sierra OS is a desktop and server operating system for Macintosh computers.


Successful exploitation of the most severe of these vulnerabilities for this threaty can result in attacker gaining the same privileges as the logged-on user, or the bypassing of security restrictions. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


THREAT INTELLIGENCE

There are currently no reports of these vulnerabilities being exploited in the wild. 😇

RISKS

Government:

  • Large and medium government entities: High

  • Small government entities: High

Businesses:

  • Large and medium business entities: High

  • Small business entities: High

Home users: Low


RECOMMENDATIONS

Contact Cyberkite via www.cyberkite.com.au/cybersecurity to book a Cybersecurity Healthcheck Session remotely (Worldwide) or onsite (Melboure Au only) or use the blue chat or contact us page to book us in We can help with the recommendations.


Apple devices although highly secure are constantly targetted due to their popularity.

We recommend the following actions be taken:

  • Apply appropriate patches/updates provided by Apple to vulnerable systems immediately after appropriate testing.

  • Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack.

  • Reminder to all staff not to download, accept, or execute files from un-trusted or unknown sources.

  • Remind to all staff not to visit untrusted websites or follow links provided by unknown or un-trusted sources.

  • Cyberkite can also assist in applying the "Principle of Least Privilege" to all systems and services to reduce chances of malicious viruses to run amuck.


LEGAL & REFERENCES



47 views

Recent Posts

See All

Comments


Welcome to Cyberkite blog! This is your go-to source for smart technology and cybersecurity insights for small business. Stay ahead of the curve with our expert tips and strategies, and join the Cyberkite community by subscribing today!

​

Knowledge is Power” – Francis Bacon / Thomas Hobbes

​

"Technology is a useful servant but a dangerous master" - Christian Lange

Cyberkite logo
  • linkedin
  • twitter
  • Instagram
  • YouTube
  • facebook
Photo of Michael Plis founder of Cyberkite

About Michael Plis

 

Michael is a technology and cybersecurity professional with over 18 years of experience. He offers unique insights into the benefits and potential risks of technology from a neurodivergent perspective. He believes that technology is a useful servant but a dangerous master. In his blog articles, Michael helps readers better understand and use technology in a beneficial way. He is also a strong supporter of mental health initiatives and advocates for creating business environments that promote good mental health.

Disclaimer: Please note that the opinions expressed by Michael or any blog assistants on this blog are his/their own and may not necessarily reflect the views of Cyberkite. Michael is neurodiverse so he needs the assistance of voice typing and AI tools to help him write and edit blog articles to and get them completed. Also we use open source images from Unsplash and Pixabay and we try to include credit to the artist of each image. Michael shares his opinions based on his extensive experience in the IT and Cybersecurity industry, learning from the world's top subject matter experts and passing on this knowledge to his audience in the hopes of benefiting them. If there is a mistake or something needs to be corrected please message using the green chat window bottom right hand corner or contact him through social media by searching for Michael Plis blogger. 

​

View our full Site Disclaimer

View our Affiliate Statement

​

bottom of page