Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases 

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.

The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on SecurityWeek.

https://www.securityweek.com/apple-patches-200-vulnerabilities-with-new-ios-27-macos-golden-gate-27-releases/




Apple’s long-rumored foldable becomes reality with the $2,000 iPhone Duo

Apple ended today’s hardware event with one of its classic “One more thing” reveals. Some smartphone makers have been offering foldable phones for the better part of a decade, but Apple has now joined the fray with the iPhone Duo after years of speculation.

This device is undeniably the most capable iPhone ever, as well as the most expensive. It’s not as spendy as many expected, though, starting at $1,999. That’s in the same range as foldables from Google and Samsung.

An iPad in your pocket

The iPhone Duo would have looked like a totally fresh take on the foldable form factor a few months ago, but Samsung has made waves with the Galaxy Z Fold 8. Like that phone, the iPhone Duo has a wider, shorter chassis. Apple prefaced its reveal with a denunciation of foldables that open into a square aspect ratio. While that shape can accommodate two portrait apps side by side pretty well, it’s bad at almost everything else, stretching single apps awkwardly and leaving videos with gargantuan black bars.

Read full article

Comments

https://arstechnica.com/gadgets/2026/09/apples-long-rumored-foldable-becomes-reality-with-the-2000-iphone-duo/




Apple debuts $129 AirPods 5 with better noise cancellation and transparency mode

Apple has debuted the new AirPods 5 with improved active noise cancellation and sound quality—aiming to provide improved listening and user features at a lower launch price than the predecessor AirPods 4.

The newest AirPods will go on sale for $129 in stores starting on September 18, according to an Apple press release accompanying the company’s “Surprise and Shine” event. Customers can also purchase AirPods 5 with a wireless charging case that provides longer battery life and on-stem volume control for $149. Preorders are already open.

This is looking like a solid deal compared to the predecessor AirPods 4. The older AirPods debuted in 2024 with a starting price of $129, but users had to pay $179 for the version with active noise cancellation.

Read full article

Comments

https://arstechnica.com/gadgets/2026/09/apple-debuts-129-airpods-5-with-better-noise-cancellation-and-transparency-mode/




Apple starts preorders for Watch Series 12, Ultra 4 with new Health Sensing System

Apple announced the Watch Series 12 and Ultra 4 today. Both include a new “Health Sensing System” and S11 chip that give the devices the “most accurate heart rate sensing in a wearable,” Apple claimed during its fall event.

Both watches will use the new S11 chip alongside the new “Health Sensing System,” allowing the watches to deliver higher-frequency heart rate and heart rate variability (HRV) measurements than prior Apple Watches.

The Health Sensing System includes redesigned photodiodes organized in a ring to capture light more efficiently and a larger electrode surface area for better skin contact. Additionally, the green LEDs on each Watch’s optical heart sensor are supposed to be bigger and more power-efficient and measure the user’s heart rate every five seconds. Users will be able to view their heart rate in real time with a new heart rate watch face special feature (also known as a complication).

Read full article

Comments

https://arstechnica.com/gadgets/2026/09/apple-watch-series-12-ultra-4-have-wearables-most-accurate-heart-rate-sensing/




Apple’s iPhone 18 Pro adds variable camera aperture and a more powerful chip

CUPERTINO, Calif.—Apple’s new iPhone 18 Pro is an iterative update that—as usual—focuses heavily on both performance and new camera features. This time around, many of the new camera features are oriented around giving the user more direct control of the image, rather than depending entirely on Apple’s computational photography assumptions.

As usual, the new iPhone has a new chip. It’s called A20 Pro, and it’s the first 2 nm chip for the iPhone. It has a 6-core CPU, with two super-cores that are up to 20 percent faster, and four efficiency cores. A 7-core GPU offers up to 40 percent improved performance and increased bandwidth.

The A20 Pro also has a new Neural Engine—the machine-learning processor on the system-on-chip—which the company says is basically two Neural Engines on one chip.

Read full article

Comments

https://arstechnica.com/gadgets/2026/09/apples-iphone-18-pro-adds-variable-camera-aperture-and-a-more-powerful-chip/




iCloud. È scontro Apple-Governo britannico su crittografia, privacy e poteri dello Stato

Apple contro il Governo britannico: nuova battaglia legale sull’accesso ai dati crittografati di iCloud

A poco più di un anno dal primo duro scontro tra Apple e il Governo britannico, la disputa sulla crittografia dei dati torna davanti ai giudici. Il colosso di Cupertino ha infatti avviato una nuova azione legale contro il Regno Unito per contestare i poteri con cui Londra può imporre alle aziende tecnologiche di facilitare l’accesso ai dati degli utenti conservati sui propri servizi cloud.

Come spiegato da Rachel Hall sul quotidiano The Guardian, la vicenda riguarda i dati archiviati su iCloud, il servizio cloud di Apple, in particolare quelli protetti dal sistema di crittografia avanzata Advanced Data Protection (ADP), che rende i contenuti leggibili esclusivamente dal proprietario dell’account.

Il nuovo ricorso di Apple contro il Governo britannico

Lo scorso mese, si legge nell’articolo, Apple ha presentato un ricorso presso l’Investigatory Powers Tribunal (IPT), il tribunale indipendente competente a valutare la legittimità delle attività dei servizi di intelligence britannici e dei poteri investigativi esercitati dallo Stato.

Secondo quanto emerge dall’ordinanza emessa dal tribunale, il Ministero dell’Interno britannico (Home Office) ha notificato ad Apple una nuova richiesta tecnica, nota come Technical Capability Notice (TCN). Si tratta di uno strumento previsto dall’Investigatory Powers Act, la controversa legge britannica che disciplina i poteri di sorveglianza e intercettazione delle autorità.

Che cos’è una Technical Capability Notice

Una Technical Capability Notice è un ordine con cui il Governo può obbligare un’azienda tecnologica ad adottare misure tecniche che consentano alle autorità di svolgere attività investigative. L’Investigatory Powers Act prevede che tali richieste possano essere utilizzate nell’ambito di indagini riguardanti, tra gli altri casi:

  • terrorismo;
  • abuso sessuale su minori;
  • gravi minacce alla sicurezza nazionale.

In pratica, il Governo può chiedere a un fornitore di servizi digitali di rendere accessibili dati che normalmente sarebbero protetti dalla crittografia. La versione più credibile è che Londra non stia pensando solo a terrorismo, criminalità organizzata o abusi online, ma voglia uno strumento utile in un ambiente di minacce multiple: Russia per la dimensione cyber-operativa, Cina per quella tecnologica e di spionaggio industriale. Detto in modo semplice, la richiesta ad Apple sembra rispondere al bisogno di non restare “ciechi” proprio nei casi che per il Regno Unito contano di più dal punto di vista geopolitico.

Dalla richiesta globale a quella limitata ai cittadini britannici

La nuova iniziativa del Governo arriva dopo un precedente confronto che aveva assunto anche una dimensione diplomatica tra Regno Unito e Stati Uniti. La prima Technical Capability Notice, notificata lo scorso anno, chiedeva ad Apple la possibilità di accedere ai dati protetti tramite Advanced Data Protection sia degli utenti britannici sia di quelli statunitensi, qualora vi fossero esigenze di sicurezza nazionale.

Dopo le forti tensioni tra Londra e Washington, il Governo britannico aveva ritirato quella richiesta. Successivamente, però, il Home Office ha emesso una seconda Technical Capability Notice, questa volta limitata esclusivamente agli utenti del Regno Unito. È proprio questa nuova richiesta ad essere oggi oggetto del ricorso presentato da Apple.

Perché Apple si oppone

Apple sostiene da tempo che creare una cosiddetta “back door”, cioè un accesso privilegiato ai dati crittografati, comprometterebbe la sicurezza dell’intero sistema. Il motivo è semplice: la crittografia end-to-end funziona proprio perché nessuno, nemmeno il fornitore del servizio, possiede le chiavi necessarie per leggere i contenuti.

Se Apple fosse tecnicamente in grado di accedere ai dati degli utenti, la stessa capacità potrebbe essere richiesta dalle autorità giudiziarie o investigative attraverso un mandato. Inoltre, qualsiasi meccanismo di accesso straordinario rappresenterebbe un potenziale punto debole sfruttabile anche da criminali informatici o altri soggetti ostili.

Secondo Apple, indebolire la crittografia significa aumentare il rischio di violazioni dei dati personali e compromettere la sicurezza di milioni di utenti.

La conseguenza: Apple ha ritirato ADP nel Regno Unito

Proprio per evitare di dover creare un sistema di accesso privilegiato, Apple aveva preso una decisione senza precedenti. Nel gennaio 2025 la società ha infatti disattivato nel Regno Unito il servizio Advanced Data Protection (è un’impostazione facoltativa che estende la crittografia end-to-end a un numero maggiore di categorie di dati su iCloud), impedendo ai nuovi utenti britannici di attivarlo e rimuovendone progressivamente la disponibilità.

La scelta ha avuto un effetto paradossale: invece di consentire allo Stato un maggiore accesso ai dati, ha ridotto il livello massimo di protezione disponibile per gli utenti britannici.

Anche Privacy International e Liberty contestano il sistema

Il caso Apple si intreccia con un altro procedimento già pendente davanti allo stesso tribunale. L’IPT ha infatti notificato il nuovo ricorso all’organizzazione per i diritti digitali Privacy International, che insieme all’associazione Liberty aveva già presentato un’azione legale contro il regime delle Technical Capability Notice.

Le due organizzazioni chiedono che il procedimento venga discusso pubblicamente, sostenendo che l’interesse collettivo alla trasparenza prevalga sulla tradizionale segretezza che caratterizza questi provvedimenti. Contestano inoltre:

  • la legittimità delle Technical Capability Notice;
  • la loro necessità;
  • il livello di segretezza previsto dall’attuale normativa britannica.

Per il prossimo mese è già stata programmata un’udienza organizzativa nella quale il tribunale dovrà stabilire come gestire i due procedimenti paralleli.

Un portavoce di Privacy International ha accolto positivamente la nuova iniziativa di Apple: “Siamo lieti di sapere che Apple sta nuovamente contestando il regime britannico degli ordini segreti. Sebbene non conosciamo il contenuto del ricorso, se riguarda gli ordini già riportati che puntano a compromettere la sicurezza dell’archiviazione iCloud, allora il ricorso di Apple, insieme al nostro e a quello di Liberty, è fondamentale per preservare la privacy e la sicurezza di tutti”.

Un test giuridico sul rapporto tra crittografia, privacy e poteri dello Stato

Né Apple né il Home Office hanno commentato il nuovo procedimento giudiziario. Entrambe le parti sono infatti soggette a restrizioni legali che impediscono di discutere pubblicamente il contenuto delle Technical Capability Notice.

Il Governo britannico continua comunque a difendere l’Investigatory Powers Act, sostenendo che la normativa preveda solide garanzie procedurali e che questi poteri vengano utilizzati soltanto quando strettamente necessari per la tutela della sicurezza nazionale e per le indagini sui reati più gravi.

La nuova causa tra Apple e il Governo britannico va ben oltre una semplice controversia nazionale. Il caso rappresenta uno dei più importanti test giuridici sul rapporto tra crittografia, privacy e poteri dello Stato. Da anni governi e forze dell’ordine chiedono strumenti che consentano di accedere ai dati cifrati per finalità investigative. Le aziende tecnologiche e le organizzazioni per i diritti digitali ribattono invece che non esiste una “back door” sicura: qualsiasi eccezione alla crittografia finirebbe inevitabilmente per indebolire la protezione di tutti gli utenti.

Novità su Google, per aggiungere Key4Biz tra le tue fonti preferite, clicca qui

Aggiungi Key4Biz tra le tue fonti preferite

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/icloud-e-scontro-apple-governo-britannico-su-crittografia-privacy-e-poteri-dello-stato/583845/




Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple announced on Monday that it has released patches for dozens of vulnerabilities discovered recently in its operating systems. 

The company patched 87 vulnerabilities with the release of iOS 26.6 and iPadOS 26.6. 

The flaws can be exploited to access sensitive user data, fingerprint users, cause a DoS condition, execute arbitrary code, delete files, modify the file system, bypass security, add contacts without authorization, spoof the UI, and escalate privileges.

In macOS Tahoe 26.6, Apple fixed 155 vulnerabilities, including ones allowing access to sensitive user data, arbitrary code execution, security bypasses, and DoS attacks.

macOS Sequoia 15.7.8 includes fixes for 138 security holes, while macOS Sonoma 14.8.8 resolves 127 issues.

Many of the vulnerabilities were patched across all of these platforms. 

Advertisement. Scroll to continue reading.

“The one worth a second look is CVE-2026-43810, where Apple notes a remote user may be able to corrupt kernel memory, because remote changes the economics of an attack chain considerably,” commented Adam Boynton, senior enterprise strategy manager at Jamf.

Roughly 100 flaws have been patched by Apple in each of its other operating systems: watchOS, tvOS, and visionOS. 

The latest Safari update fixes nearly a dozen vulnerabilities, including ones that can be exploited to access sensitive user data or crash the browser.

The advisories do not mention in-the-wild exploitation. Additional details are available in Apple’s security advisories. 

Related: Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari

Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones

Related: Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention

https://www.securityweek.com/apple-patches-87-vulnerabilities-in-ios-155-in-macos-tahoe/




Newly discovered PamStealer isn’t your typical macOS malware

Researchers have found a never-before-seen piece of macOS malware that combines a series of clever tradecraft to infect Macs with stealthy, custom-developed credential-stealing code.

The malware is delivered in two stages. The first is distributed in a disk image that masquerades as Maccy, a clipboard manager for Macs. It’s compiled as AppleScript that is notable for the way it delivers the second stage. The malware is named PamStealer because the Rust-written infostealer uses the Pluggable Authentication Modules interface built into macOS to validate the target’s login password before sending it to an attacker-controlled server.

A quieter execution chain

The use of both disk image and AppleScript is common in malware for Macs. More unusual is the way PamStealer combines them to gain stealth. When the AppleScript is double-clicked, it’s opened in the macOS Script Editor, where the malicious functionality is buried deep within the file.

“Rather than relying on shell commands such as curl or zsh, the AppleScript executes a self-contained JavaScript for Automation (JXA) downloader that retrieves and stages the payload using native Objective-C APIs,” researchers from Jamf, a security firm for macOS users, wrote. “Combined with a Rust-based second stage and a password capture workflow that validates credentials locally through PAM, the result is a quieter execution chain than we typically observe in commodity macOS stealers.”

When a user, expecting to install a trustworthy clipboard manager, encounters the disk image, they’re prompted to press Command-R immediately after double-clicking it. This command executes malicious code inside the AppleScript directly. It also allows the execution to bypass com.apple.quarantine, a macOS attribute that provides warnings and restrictions when executable files have been downloaded from the Internet.

As Jamf explained:

PamStealer combines a recently emerging delivery surface with a less familiar payload. While the clickable .scpt and Script Editor lure build on tradecraft that is already gaining adoption across the macOS threat landscape, the malware distinguishes itself through a self-contained JXA dropper, a Rust-based second stage, and a password capture workflow that validates credentials locally through PAM before harvesting them. That second stage puts considerable effort into staying hidden, masquerading as Finder, encrypting its command-and-control traffic, and holding back prompts like the Full Disk Access request for as long as forty minutes so its activity does not line up with launch. Together, these behaviors illustrate how commodity macOS stealers continue to evolve, adopting quieter execution chains and native implementations that reduce traditional detection opportunities while remaining compatible with standard macOS features.

The first stage puts its payload inside an app bundle that impersonates real components built into macOS. The component changes from sample to sample of the malware. Finder.app under com.apple.finder.core or com.apple.finder.monitor, and a Software Update.app under com.apple.security.daemon, are two examples. In either case, they run hidden. They also display macOS’s genuine Finder.icns as its icon.

https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy/




Apple takes Epic fight over app store fees to the Supreme Court

According to Reuters, the Supreme Court will likely hear the case during its next term, which begins this October.

Apple’s math will likely be challenged

Apple’s filing said that Epic is hoping that the court fight will end with Apple charging a de minimis rate to developers who want to have more control over how transactions are completed in their apps.

In litigation that has been paused during the Supreme Court review, Epic expects to force Apple to show receipts explaining why commission rates are so high.

So far, Apple has claimed that commission fees “ensure that Apple can continue to receive compensation for use of its IP-protected tools, technologies, and services—the very things that attract developers and enable app creation.”

For example, with Epic, Apple claims that purchases like even a single “skin” that Fortnite players buy to make their characters look unique require a fee. Those commissions help Apple develop and update “the iPhone screen that displays it, the iPhone touch controls that direct the virtual character, the Apple silicon chip that processes all iOS software, the app development tools Epic used to build Fortnite for iOS, and the App Store platform that downloads, updates, and maintains the app,” their filing said.

If the Supreme Court sides with Apple and reverses the contempt finding, Apple is hoping to wriggle out of sharing “confidential business data regarding the company’s decision-making concerning the App Store, its implementation of linked-out purchases for developers, and its internal discussions regarding compliance with the injunction.”

Meanwhile, the UK is also hoping to analyze Apple’s actual costs. The CMA has suggested that Apple “could still levy fees” for allowing link-outs, “but that such charges would have to be applied fairly,” the Guardian reported. Like Epic, the Coalition for App Fairness suggested that any app store developer “charges should be justified by ‘transparent data’ from Apple and Google explaining any underlying cost to the tech companies.”

Apple did not immediately respond to Ars’ request to comment.

https://arstechnica.com/tech-policy/2026/06/apple-takes-epic-fight-over-app-store-fees-to-the-supreme-court/




Russian citizens told “switch to Android” after Apple blocks key Russian apps

VK Group, the developers of VKontakte and related services, issued its own statement complaining that “Apple has removed VK apps from the App Store without warning or explanation… VK has never been subject to sanctions nor included on sanctions lists, a fact confirmed by numerous legal opinions from international and US counsel. Apple has long been in possession of these official legal opinions and all relevant information. Nevertheless, Apple unilaterally removed VK apps without prior notice… We consider these actions by Apple regarding Russian users to be unjustified and unacceptable.” (Translation from Russian through Google Translate.)

VK Group also stressed that its Android apps “remain fully functional—including updates, notifications, and other features—and are available via RuStore, Google Play, Huawei AppGallery, Samsung Store, Xiaomi Store, and official product websites.”

This appears to be the new line from the Kremlin, as well. A Russian Telegram channel that reports on Peskov’s comments quoted him yesterday as saying that Apple perhaps could not be “trusted as a commercial service provider” and that the blocks are part of a pattern of “decisions by Apple that are, to put it mildly, bizarre.” (Translation from Russian through Google Translate.)

Still, despite the posturing, Peskov knows the score; there’s little Russia can do about the situation. So instead, he ended with an appeal to users. “There is always an immediate solution,” he said, “switch to Android, switch to our systems, switch to our equivalent service, and continue using the services you love.”

https://arstechnica.com/gadgets/2026/06/russian-citizens-told-switch-to-android-after-apple-blocks-key-russian-apps/