Apple Inc seems to be learning that it is not immune to cyber attacks. On Tuesday Apple released the latest update to its iOS software for the iPhone, iPod touch and iPad, which addresses bugs that could prevent the new iPad from switching between 2G and 3G networks.
The update comes barely days after Kaspersky CEO Eugene Kaspersky made a statement CBR, that he felt that Apple was a long way behind Microsoft when it comes to security and will have to change the ways it approaches updates following the recent malware attacks.
Apple Inc logo
The update also is aimed at fixing bugs that affected AirPlay video playback in some circumstances, as well as security issues concerning Apple’s Safari browser. The update can be downloaded via Apple’s Website, iTunes, or over the air on compatible devices, and takes up about 50 MB of space on the device.
The details of the software update is as follows:
¦Safari
Available for: iPhone 3GS, iPhone 4, iPhone 4S, iPod touch (3rd generation) and later, iPad, iPad 2
Impact: A maliciously crafted website may be able to spoof the address in the location bar
Description: A URL spoofing issue existed in Safari. This could be used in a malicious web site to direct the user to a spoofed site that visually appeared to be a legitimate domain. This issue is addressed through improved URL handling. This issue does not affect OS X systems.
CVE-ID
CVE-2012-0674 : David Vieira-Kurz of MajorSecurity (majorsecurity.net)
¦WebKit
Available for: iPhone 3GS, iPhone 4, iPhone 4S, iPod touch (3rd generation) and later, iPad, iPad 2
Impact: Visiting a maliciously crafted website may lead to a cross-site scripting attack
Description: Multiple cross-site scripting issues existed in WebKit.
CVE-ID
CVE-2011-3046 : Sergey Glazunov working with Google’s Pwnium contest
CVE-2011-3056 : Sergey Glazunov
¦WebKit
Available for: iPhone 3GS, iPhone 4, iPhone 4S, iPod touch (3rd generation) and later, iPad, iPad 2
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue existed in WebKit.
CVE-ID
CVE-2012-0672 : Adam Barth and Abhishek Arya of the Google Chrome Security Team
The update also contained a camera improvement, boosting the reliability of using the HDR option for photos taken using the Lock Screen shortcut, and fixes an issue where the ‘Unable to purchase’ alert could be displayed after a successful purchase. In addition to the bug fixes, the update also patches some serious security vulnerabilities, including a number of patches in the WebKit rendering engine, such as a memory corruption issue. The patch also fixed a security issue in Safari, which uses WebKit.
Source:http://www.ciol.com/Mobile-Security/News-Reports/Apple-updates-iOS-511-software/162783/0/

