Skip to main content

Apple chaiOS DoS Vulnerability

A vulnerability has been discovered in Apple's iOS and macOS operating systems that can cause a device to freeze or restart.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability has been discovered in Apple's iOS and macOS operating systems that can cause a device to freeze or restart.

Affected platforms

The following platforms are known to be affected:

Threat details

This denial-of-service (DoS) attack uses a specially-crafted webpage containing large amounts of useless metadata. When a user attempts to open a link to this page using the Messages application, it causes the application to crash. Alongside this, the device may trigger a "respring" (rebooting the SpringBoard process and locking the user out of the device) or a full reboot of the device.


Remediation steps

Type Step
Apple have released updates to patch this vulnerability. Users are encouraged to apply the iOS 11.2.5 and macOS 10.13.3 updates immediately.

Last edited: 17 February 2020 12:37 pm