search
HomeCommon ProblemiOS 15.2.1 and iPadOS 15.2.1 address HomeKit vulnerability

iOS 15.2.1 and iPadOS 15.2.1 address HomeKit vulnerability

May 14, 2023 am 08:58 AM
iosloopholessmart homehomekithomekit vulnerability

Apple today released iOS 15.2.1 and iPadOS 15.2.1. These small updates include important security fixes for known HomeKit vulnerabilities first discovered last year.

iOS 15.2.1 和 iPadOS 15.2.1 解决 HomeKit 漏洞
According to Apple's updated security support document, it addresses an issue that could allow a maliciously crafted ‌HomeKit‌ name to cause a denial of service, preventing iPhones and iPads from working.

Apple says this was caused by a resource exhaustion issue, which has now been resolved through improved input validation.

The vulnerability, dubbed "doorLock," operates by changing the name of a ‌HomeKit‌ device to one that is longer than 500,000 characters.

Attempting to load such a large string will cause the iOS device to enter a denial of service state, and a force reset is the only way to recover. Unless a backup is available, resetting the device will result in data loss, and logging back into the affected iCloud account associated with the corrupted "HomeKit" device name may re-trigger the error.

Apple partially fixed the bug in iOS 15.1 by limiting the length of names that can be set for ‌HomeKit‌ devices or apps, but it doesn't completely resolve the issue, as a malicious actor who exploited the flaw could use Home invitations instead The device triggers the attack.

Since this error can result in data loss and device reset at best, it's worth updating to the iOS and iPadOS 15.2.1 update immediately.

The above is the detailed content of iOS 15.2.1 and iPadOS 15.2.1 address HomeKit vulnerability. For more information, please follow other related articles on the PHP Chinese website!

Statement
This article is reproduced at:云东方. If there is any infringement, please contact admin@php.cn delete

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

DVWA

DVWA

Damn Vulnerable Web App (DVWA) is a PHP/MySQL web application that is very vulnerable. Its main goals are to be an aid for security professionals to test their skills and tools in a legal environment, to help web developers better understand the process of securing web applications, and to help teachers/students teach/learn in a classroom environment Web application security. The goal of DVWA is to practice some of the most common web vulnerabilities through a simple and straightforward interface, with varying degrees of difficulty. Please note that this software

VSCode Windows 64-bit Download

VSCode Windows 64-bit Download

A free and powerful IDE editor launched by Microsoft

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

Atom editor mac version download

Atom editor mac version download

The most popular open source editor

SAP NetWeaver Server Adapter for Eclipse

SAP NetWeaver Server Adapter for Eclipse

Integrate Eclipse with SAP NetWeaver application server.