iOS and the WebP Vulnerability
ID: 4f299761-9b76-5049-bc2c-25d6714fcc9b
STIX ID: report--4f299761-9b76-5049-bc2c-25d6714fcc9b
Feed Name: Zimperium Blog
This Zimperium retrospective reviews CVE-2023-4863 (the WebP heap overflow exploited in the BLASTPASS zero-day) and analyzes iOS patching behavior, focusing on Flutter apps. Zimperium sampled ~8,000 iOS apps in late 2023 and again in Q1 2024, finding that a high percentage of Flutter apps remained vulnerable months after a patch was released (100% in the late-2023 sample and ~90% in early-2024 sampling), highlighting slow patch adoption and recommending pre-release app vetting, continuous checks, and usage of Zimperium’s MAPS suite to detect and remediate vulnerable apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
