Site icon The Mac Security Blog

50 Shades of Security Fixes: iOS 9.2 Update Available

Apple has released iOS 9.2 for iPhones and iPads, patching a wide range of security bugs while adding several new feature updates. iOS 9.2 includes fixes for a combined 50 vulnerabilities, found by researchers at Apple and other vendors, many of which relate to the remote execution of code and remote access to system privileges.

iOS 9.2 is available for the following Apple devices: iPhone 4s and later, iPod touch (5th generation) and later, iPad 2 and later.

One of the more notable security fixes addresses a flaw (CVE-2015-7080) that could allow people to use Siri on someone else’s iPhone or iPad to read notifications of content that is set to not be displayed at the lock screen. Another bug fix of particular note (CVE-2015-7094) impacts both iOS and OS X, whereas “an attacker with a privileged network position may be able to bypass HSTS,” Apple warned in its security bulletin.

As noted by Sean Michael Kerner at eWeek, an HSTS bypass comes with several risks.

HSTS is a security configuration that forces Web connections to occur over Secure Sockets Layer/Transport Layer Security (SSL/TLS) encrypted communications. The risk of an HSTS bypass is that a site that should only be available over SSL/TLS is accessible over a nonencrypted connection, where an attacker could easily view a user’s data traffic.

Altogether, the following describes the 50 vulnerabilities patched in iOS 9.2:

Apple iOS users can download and install the iOS 9 update through iTunes or through your device settings (select General > Software Update).

Share this: