Close X
Saturday, November 16, 2024
ADVT 
National

Apple Security Breach Could Impact Canadians With iPhones And iPads

The Canadian Press, 21 Sep, 2015 12:28 PM
    TORONTO — Apple announced a rare security breach over the weekend that means some Canadians may have unwittingly infected their iPhones and iPads with malware that could expose their iCloud passwords and other personal data.
     
    Apple Inc. has removed some applications from its app store after developers in China were tricked into using software tools that added malicious code to their work.
     
    Apple hasn't provided details about which companies' apps were affected.
     
    But Tencent Ltd. said its popular WeChat app was hit; the company released a new version after spotting the offending code. Chinese news reports said others affected included banks, an airline and a popular music service.
     
    Many of the affected apps were only available on the App Store in China, yet some that were reportedly infected by the malware — including WeChat, business card rolodex CamCard and file extractor WinZip — are available in Canada.
     
    Users are advised to uninstall the affected apps or update to the latest version released after the malware was discovered, and to change their iCloud passwords.
     
    The malicious code spread through a counterfeit version of Apple's Xcode tools used to create apps for its iPhones and iPads, according to the company. It said the counterfeit tools spread when developers obtained them from "untrusted sources" rather than directly from the company.
     
     
    The malicious software collects information from infected devices and uploads it to outside servers, according to Palo Alto Networks, a U.S.-based security firm. The company said the breach could result in fake password prompts aimed at harvesting iCloud details or other logins.
     
    It was first publicized last week by security researchers at Alibaba Group, the Asian e-commerce giant, who dubbed it XcodeGhost.
     
    The creators of the malware took advantage of public frustration with Beijing's Internet filters, which hamper access to Apple and other foreign websites. That prompts some people to use copies of foreign software or documents that are posted on websites within China to speed up access.
     
    "Sometimes network speeds are very slow when downloading large files from Apple's servers," wrote Claud Xiao, a Palo Alto Networks researcher, on its website. Due to the large size of the Xcode file, "some Chinese developers choose to download the package from other sources or get copies from colleagues."
     
    Companies with apps that were affected include taxi-hailing service Didi Kuaidi, Citic Industrial Bank, China Southern Airlines and the music service of NetEase, a popular Web portal, according to the newspaper Yangcheng Evening News.
     
     
    The incident is the only the sixth time malicious software is known to have made it through Apple's screening process for products on its App Store, according to Xiao.

    MORE National ARTICLES

    Public Health Officials Report Outbreak Of 24 E. Coli Cases Across 4 Provinces

    Public Health Officials Report Outbreak Of 24 E. Coli Cases Across 4 Provinces
    TORONTO — Public health officials are investigating an outbreak of E. coli infections that occurred across four provinces this summer.

    Public Health Officials Report Outbreak Of 24 E. Coli Cases Across 4 Provinces

    Sen. Mike Duffy fraud trial continues in Ottawa, heading for break

    Sen. Mike Duffy fraud trial continues in Ottawa, heading for break
    OTTAWA — The Mike Duffy trial rolls on today in Ottawa following one of the most hostile confrontations yet between witness and lawyer.

    Sen. Mike Duffy fraud trial continues in Ottawa, heading for break

    Senior Police Officer Found Guilty Of 3 Charges In G20 Disciplinary Hearing

    Senior Police Officer Found Guilty Of 3 Charges In G20 Disciplinary Hearing
    TORONTO — The most senior police officer charged over mass arrests made during the Toronto's G20 summit five years ago has been found guilty on three out of five offences at a disciplinary hearing.

    Senior Police Officer Found Guilty Of 3 Charges In G20 Disciplinary Hearing

    Delhi Girl Jasleen Kaur Vs Her ‘Harasser’ Sarvjeet Singh: Who Is Telling The Truth

    Delhi Girl Jasleen Kaur Vs Her ‘Harasser’ Sarvjeet Singh: Who Is Telling The Truth
    Sarvjeet Singh aka Sunny, the accused in the case, alleged that Jasleen is an AAP supporter and is doing it all for political mileage and fame.

    Delhi Girl Jasleen Kaur Vs Her ‘Harasser’ Sarvjeet Singh: Who Is Telling The Truth

    'Birthday-Card Bandit' Dustin Crocker Sentenced To 1-Year Probation For Theft At Boy's Party

    'Birthday-Card Bandit' Dustin Crocker Sentenced To 1-Year Probation For Theft At Boy's Party
    Thirty-nine-year-old Dustin Crocker pleaded guilty to theft under $5,000 last week.

    'Birthday-Card Bandit' Dustin Crocker Sentenced To 1-Year Probation For Theft At Boy's Party

    Delhi Girl Jasleen Kaur’s Facebook Post Of Abusive Eve-Teaser Goes Viral; Police Arrest Accused

    Delhi Girl Jasleen Kaur’s Facebook Post Of Abusive Eve-Teaser Goes Viral; Police Arrest Accused
    After reporting the matter to police, the girl uploaded the photograph of the accused on Facebook with the post soon going viral. The accused, identified as Sarabjit Singh (26), has been arrested 

    Delhi Girl Jasleen Kaur’s Facebook Post Of Abusive Eve-Teaser Goes Viral; Police Arrest Accused