{"id":149929,"date":"2025-09-11T21:53:07","date_gmt":"2025-09-11T21:53:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/149929\/"},"modified":"2025-09-11T21:53:07","modified_gmt":"2025-09-11T21:53:07","slug":"apples-big-bet-to-eliminate-the-iphones-most-targeted-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/149929\/","title":{"rendered":"Apple\u2019s Big Bet to Eliminate the iPhone\u2019s Most Targeted Vulnerabilities"},"content":{"rendered":"<p>Apple launched a <a href=\"https:\/\/www.wired.com\/story\/apple-iphone-17-iphone-air-and-iphone-17-pro\/\" rel=\"nofollow noopener\" target=\"_blank\">slate of new iPhones<\/a> on Tuesday loaded with the company&#8217;s new A19 and A19 Pro chips. Along with an <a href=\"https:\/\/www.wired.com\/story\/exciting-camera-features-on-apples-new-iphone-17-lineup\/\" rel=\"nofollow noopener\" target=\"_blank\">ultrathin iPhone Air and other redesigns<\/a>, the new phones come with a less flashy upgrade that could turn out to be the true killer feature. A security improvement called Memory Integrity Enforcement combines always-on, chip-level protections with software defenses in an effort to harden iPhones against the most common\u2014and commonly exploited\u2014software vulnerabilities.<\/p>\n<p class=\"paywall\">In recent years, a movement has been steadily growing across the global tech industry to address a ubiquitous and insidious type of bugs known as memory-safety vulnerabilities. A computer&#8217;s memory is a shared resource among all programs, and memory safety issues crop up when software can pull data that should be off limits from a computer&#8217;s memory or manipulate data in memory that shouldn&#8217;t be accessible to the program. When developers\u2014even experienced and security-conscious developers\u2014write software in ubiquitous, historic programming languages, like C and C++, it&#8217;s easy to make mistakes that lead to memory safety vulnerabilities. That&#8217;s why proactive tools like <a href=\"https:\/\/www.wired.com\/story\/rust-secure-programming-language-memory-safe\/\" rel=\"nofollow noopener\" target=\"_blank\">special programming languages<\/a> have been proliferating with the goal of making it structurally impossible for software to contain these vulnerabilities, rather than attempting to avoid introducing them or catch all of them.<\/p>\n<p class=\"paywall\">\u201cThe importance of memory safety cannot be overstated,\u201d the US National Security Agency and Cybersecurity and Infrastructure Security Agency <a href=\"https:\/\/media.defense.gov\/2025\/Jun\/23\/2003742198\/-1\/-1\/0\/CSI_MEMORY_SAFE_LANGUAGES_REDUCING_VULNERABILITIES_IN_MODERN_SOFTWARE_DEVELOPMENT.PDF\" rel=\"nofollow noopener\" target=\"_blank\">wrote in a June report<\/a>. \u201cThe consequences of memory safety vulnerabilities can be severe, ranging from data breaches to system crashes and operational disruptions.\u201d<\/p>\n<p class=\"paywall\">Apple&#8217;s Swift programming language, released in 2014, is memory-safe. The company says it has been writing new code in Swift for years as well as attempting to strategically overhaul and rewrite existing code in the memory-safe language to make its systems more secure. This reflects the challenge of memory safety across the industry, because even if new code is written more securely, the world&#8217;s software was all written in memory-unsafe languages for decades. And while, in general, Apple&#8217;s locked down ecosystem has so far succeeded at preventing widespread malware attacks against iPhones, motivated attackers, particularly <a href=\"https:\/\/www.wired.com\/story\/us-spyware-investment\/\" rel=\"nofollow noopener\" target=\"_blank\">spyware makers<\/a>, do still develop complex iOS exploit chains at high cost to target specific victims&#8217; iPhones.<\/p>\n<p class=\"paywall\">Even with the work Apple has done to begin overhauling its code for memory safety, the company has found that these rarefied attack chains virtually always still include exploitation of memory bugs.<\/p>\n<p class=\"paywall\">\u201cKnown mercenary spyware chains used against iOS share a common denominator with those targeting Windows and Android: they exploit memory safety vulnerabilities, which are interchangeable, powerful, and exist throughout the industry,\u201d Apple wrote in its <a data-offer-url=\"https:\/\/security.apple.com\/blog\/memory-integrity-enforcement\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/security.apple.com\/blog\/memory-integrity-enforcement\/&quot;}\" href=\"https:\/\/security.apple.com\/blog\/memory-integrity-enforcement\/\" rel=\"nofollow noopener\" target=\"_blank\">Memory Integrity Enforcement announcement<\/a> on Wednesday.<\/p>\n<p class=\"paywall\">Apple has increasingly invested in memory safety with Swift and secure memory allocators that manage which regions of memory are \u201callocated\u201d and \u201cdeallocated\u201d for which data\u2014a major factor in, and source of, memory safety vulnerabilities. But Memory Integrity Enforcement itself was originally inspired by work at the hardware level to protect code integrity even when a system has suffered memory corruption.<\/p>\n","protected":false},"excerpt":{"rendered":"Apple launched a slate of new iPhones on Tuesday loaded with the company&#8217;s new A19 and A19 Pro&hellip;\n","protected":false},"author":2,"featured_media":149930,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[517,7257,1065,4535,4536,7270,74,11202],"class_list":["post-149929","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-apple","tag-cybersecurity","tag-hacks","tag-ios","tag-iphone","tag-security","tag-technology","tag-vulnerabilities"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/149929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=149929"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/149929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/149930"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=149929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=149929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=149929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}