Ó¦ÓÃÊÐËÁÈÏ֤ϵͳµÄµ×²ãÂß¼
ÔÚiosϵͳ¼Ü¹¹ÖУ¬ÆóÒµ¼¶Ö¤ÊéÊðÃû£¨Enterprise Certificate Signing£©ÊÇÈ·±£Ó¦ÓÃÇå¾²µÄ½¹µã·ÀµØ¡£Ã¿¿î¹Ù·½ÈÏÖ¤Èí¼þ¶¼Ðèͨ¹ýÆ»¹ûɳºÐ»úÖÆµÄ°ËÖØÇå¾²¼ì²â£¬Éæ¼°¶¯Ì¬´úÂëɨÃè¡¢ÄÚ´æÊ¹Óüà²âµÈÒªº¦ÊÖÒղ㡣ÓëÖ®Ïà¶Ô£¬²¿·ÖδÂÄÀúÖ¤µÄËùν"¹ÙÆÓÖ±°æ"×°Öðü³£ÈƹýApp StoreÉóºËϵͳ£¬Æä°üÀ¨µÄ¶ñÒâSDK¿ÉÄÜÇÔÈ¡Óû§Òþ˽Êý¾Ý¡£Æ¾Ö¤2023ÄêÒÆ¶¯Çå¾²Ä걨ͳ¼Æ£¬´ËÀ಻·¨ÇþµÀÏÂÔØÓ¦ÓõÄϵͳȨÏÞÀÄÓð¸Àýͬ±ÈÉÏÉý37%¡£
µÚÈý·½Æ½Ì¨µÄÇå¾²Òþ»¼Æ×ϵ
·Ç¹Ù·½·Ö·¢ÇþµÀ±£´æµÄÊÖÒÕΣº¦·ºÆð¶àÔª»¯ÌØÕ÷¡£Í¨¹ýÄæÏò¹¤³Ì²âÊÔ·¢Ã÷£¬²¿·Ö±»ÆÆ½âµÄipaÎļþ£¨iOS Application Package£©±»Ö²ÈëÔ¶³Ì¿ØÖÆÄ£¿é£¬ÆäͨѶÐÒé¶Ë¿Ú¾³£Î´°´Apple¿ª·¢Õ߹淶ÉèÖüÓÃÜËíµÀ¡£¸üÖµµÃСÐĵÄÊÇ£¬ÕâЩ¾Óɶþ´Î°ü×°µÄ×°Öðü»áαÔìÈí¼þÊý×ÖÊðÃû£¨Code Signature£©£¬ÔÚ×°±¸ÈÕÖ¾ÖÐÏÔʾΪ"ÒÑÑéÖ¤"״̬£¬ÊµÖÊÈ´¿ªÆôÁËÏà»ú¡¢Âó¿Ë·çµÈÃô¸ÐÓ²¼þµÄµ×²ãŲÓÃȨÏÞ¡£
×°±¸Çå¾²·À»¤ÊÖÒÕÉý¼¶Â·¾¶
iOS 17ϵͳ×îÐÂÒýÈëµÄÒþ˽ȨÏÞ×·Ëݹ¦Ð§£¨Privacy Tracing Module£©ÄÜÓÐÓÃʶ±ðÒì³£ºǫ́»î¶¯¡£Óû§¿ÉÔÚÉèÖÃÖеÄ"Òþ˽ÆÊÎö"Ä£¿é²éÔĸ÷Ó¦ÓõÄϵͳŲÓÃÈÕÖ¾£¬µ±¼ì²âµ½¸ßƵ¶¨Î»ÇëÇó»òͨѶ¼¶ÁÈ¡ÐÐΪʱ£¬ÏµÍ³»á×Ô¶¯´¥·¢Çå¾²¸ôÀë»úÖÆ¡£ÅäºÏ×°±¸ÖÎÀíÆ÷£¨Mobile Device Management£©µÄÉèÖÃÕ½ÂÔ£¬¿ÉÇ¿ÖÆ×è¶ÏδÂÄÀúÖ¤Ö¤ÊéµÄÓ¦ÓóÌÐòÔËÐС£
Õýµ±×°ÖÃ;¾¶µÄÊÖÒÕÑéÖ¤ÒªÁì
Çø·Ö¹Ù·½ÈªÔ´Ó¦ÓÃÐè¹Ø×¢Èý¸öÊÖÒÕά¶È£ºÊǼì²éÓ¦ÓÃÐÎòÎļþµÄÖ¤Êé½ÒÏþ»ú¹¹£¬Õý°æÈí¼þÖ¤Êé¾ùÏÔʾΪApple Worldwide Developer Relations£»Ó¦ºË¶Ô×°ÖðüµÄ¹þÏ£Öµ£¨SHA-256 Checksum£©£¬¿ÉÔÚÆ»¹û¿ª·¢Õß¹ÙÍøÑéÖ¤±àÒë²úÆ·µÄΨһÐÔ£»Ðè×¢ÖØÓ¦ÓÃÊ×´ÎÆô¶¯Ê±µÄ¹«Ö¤ÑéÖ¤£¨Notarization£©Ê±³¤£¬Í¨¹ý¶ñÒâ´úÂë×¢ÈëµÄαӦÓÃÍùÍùȱ·¦ÍêÕûµÄ¹«Ö¤Á÷³Ì¡£
ϵͳ¼¶Çå¾²·À»¤µÄÊÖÒÕʵ¼ù
½¨ÒéÓû§¿ªÆôϵͳÍêÕûÐÔ±£»¤£¨System Integrity Protection£©¹¦Ð§£¬¸Ã»úÖÆÍ¨¹ýÄں˼¶·À»¤ËøËÀÃô¸ÐϵͳĿ¼¡£µ±¼ì²âµ½Î´¾ÊÚȨµÄ´úÂëÐÞ¸Äʱ£¬ÏµÍ³»á×Ô¶¯»Ö»Ø¸´Ê¼Îļþ½á¹¹¡£ÅäºÏApp´«ÊäÇå¾²£¨ATS£©ÐÒéµÄÇ¿ÖÆÊµÑ飬ÄÜÓÐÓÃ×赲ͨ¹ýαװµÄÖÐÐÄÈ˹¥»÷£¨MITM Attack£©£¬È·±£Ó¦ÓÃͨѶÀú³ÌµÄÊý¾Ý¼ÓÃÜÇ¿¶È¡£
ÔÚÊý×ÖÇå¾²·À»¤ÁìÓò£¬ÏµÍ³¼Ü¹¹µÄ·À»¤ÄÜÁ¦ÓëÓû§µÄÇå¾²ÒâʶһÂÉÖ÷Òª¡£iOSÉú̬ͨ¹ý¶à²ãÊÖÒÕÑéÖ¤ÐÞ½¨Ó¦ÓÃÇå¾²·ÀµØ£¬µ«ÈËΪ¹æ±Ü¹Ù·½ÈÏÖ¤»úÖÆÈÔ¿ÉÄÜ·¿ªÏµÍ³·À»¤È±¿Ú¡£½¨ÒéÖÕ¶ËÓû§ÑÏ¿áÖ´ÐÐϵͳ¸üÐÂÕ½ÂÔ£¬ÉÆÓÃ×°±¸×Ô´øµÄÇå¾²ÆÊÎö¹¤¾ß£¬ÅäºÏά»¤Òƶ¯Ó¦ÓÃÉú̬µÄÁ¼ÐÔÉú³¤¡£
Ò»¡¢°æ±¾µü´úµÄÊÖÒÕÍ»ÆÆ
V92.3.4°æ±¾ÒýÈëµÄ²î·Ö¸üÐÂÊÖÒÕÏÔÖøÓÅ»¯ÁË×°ÖðüÌå»ý£¬Í¨¹ý¶¯Ì¬Ä£¿é»¯ÊÖÒÕʵÏÖ½¹µã¹¦Ð§×ÔÁ¦¼ÓÔØ¡£¿ª·¢ÕßÌØÊâÇ¿»¯ÁËÔËÐÐʱȨÏÞÖÎÀíϵͳ£¬Ã¿´ÎŲÓÃÃô¸ÐAPIʱ¶¼»á´¥·¢Ë«ÖØÑéÖ¤»úÖÆ¡£¸Ã°æ±¾Ó밲׿12¼°ÒÔÉÏϵͳµÄÉî¶ÈÊÊÅäÂʵִï98.7%£¬ÔÚ»ªÎªºèÃÉϵͳµÄ¼æÈݲâÊÔÖÐÒ²»ñµÃ82·ÖµÄ¸ß·ÖÆÀ¼¶¡£
¶þ¡¢¹Ù·½ÇþµÀºËÑéÒªÁìÂÛ
Ñé֤װÖðüÊðÃû³ÉΪȷÈϹٷ½°æ±¾µÄÖ÷ÒªÊÖÒÕÊֶΣ¬Ã¿¸öÕý°æAPK¶¼°üÀ¨¿ª·¢ÕßרÊôµÄÊý×ÖÖ¤ÊéÖ¸ÎÆ¡£Óû§¿Éͨ¹ý±È¶ÔAPK ChecksumУÑéÖµÓë¹ÙÍø¹«Ê¾Êý¾ÝÈ·±£ÎļþÍêÕûÐÔ¡£²¿·ÖµÚÈý·½Ó¦ÓÃÊÐËÁËäÌṩÏÂÔØÐ§ÀÍ£¬µ«ÐèÒªÖØµãºË²éÆäÊÇ·ñÓµÓÐCSA£¨ÄÚÈÝÇ徲ͬÃË£©ÈÏÖ¤×ÊÖÊ¡£
Èý¡¢¹¦Ð§Ä£¿éµÄÖÇÄÜÉèÖÃ
¶¯Ì¬Çø·ÖÂʵ÷ÀíÊÖÒÕʹ¸Ã°æ±¾ÔÚµÍÅä×°±¸ÉÏÈÔÄܼá³Ö45fpsµÄÁ÷ͨÔËÐÐˮƽ¡£Ð¼ÓÈëµÄÖÇÄÜ»º´æÖÎÀíϵͳͨ¹ý»úеѧϰËã·¨Õ¹ÍûÓû§ÐÐΪģʽ£¬Æ½¾ù½ÚÔ¼37%µÄ´ø¿íÏûºÄ¡£Òþ˽ɳºÐ¹¦Ð§¿É½¨Éè×ÔÁ¦ÔËÐÐÇéÐΣ¬ÓÐÓøôÀëÓ¦ÓÃÊý¾ÝÓëϵͳ½¹µã×é¼þ¡£
ËÄ¡¢Çå¾²·À»¤µÄÒªº¦Òªµã
×°ÖÃǰµÄÉî¶È¼ì²âÐè½èÖúVT£¨VirusTotal£©ÒýÇæ¾ÙÐжàά¶ÈɨÃ裬¸Ãƽ̨ÕûºÏ68¼ÒÇå¾²³§É̵IJéɱÄÜÁ¦¡£ÔËÐÐʱ·À»¤Ó¦ÆôÓÃϵͳ×Ô´øµÄRASP£¨ÊµÊ±Ó¦ÓÃ×ÔÎÒ±£»¤£©Ä£¿é£¬Äܼ´Ê±×è¶Ï99.3%µÄÒÑÖª¹¥»÷ÏòÁ¿¡£°´ÆÚÕûÀíÊ£ÓàÀú³ÌÎļþ¿É×èÖ¹±¬·¢½©Ê¬Ð§ÀÍÏûºÄϵͳ×ÊÔ´¡£
Î塢ʹÓÃЧÄÜÓÅ»¯Êµ¼ù
¹Ø±Õ·ÇÐëÒªºǫ́ЧÀÍ¿ÉʹÄÚ´æÕ¼ÓýµµÍ42%£¬ÔÚ¿ª·¢ÕßÑ¡ÏîÖÐÏÞÖÆºǫ́Àú³ÌÊýÄ¿¿ÉÌáÉý19%µÄÏìÓ¦ËÙÂÊ¡£¿ªÆôÓ²¼þ¼ÓËÙ½âÂ빦Чºó£¬1080PÊÓÆµäÖȾЧÂÊÌáÉý27%¡£½¨ÒéÅäºÏϵͳ¼¶½Úµç¼Æ»®Ê¹Ó㬲âÊÔÊý¾ÝÏÔʾ¿ÉÑÓÉì×°±¸Ðøº½Ê±¼ä1.8Сʱ¡£
Áù¡¢Ö´·¨ºÏ¹æÓëÊÖÒÕÂ×Àí
ÒÀ¾Ý¡¶ÍøÂçÇå¾²·¨¡·µÚ41Ìõ»®¶¨£¬ÈκÎÓ¦ÓõĴ洢ÊÚȨ¶¼Ðè»ñµÃÓû§ÕÑʾÔ޳ɡ£ÊÖÒÕÂ×ÀíÒªÇ󿪷¢Õß²»µÃÖ²ÈëÒþ²ØµÄÊý¾ÝÍøÂçÄ£¿é£¬µÚÈý·½SDK¼¯³É±ØÐèͨ¹ýGDPR£¨Í¨ÓÃÊý¾Ý±£»¤ÌõÀý£©ºÏ¹æÉó²é¡£Óû§Ó¦°´ÆÚºË²éÓ¦ÓÃȨÏÞÁÐ±í£¬ÊµÊ±³·»Ø²»ÐëÒªµÄ»á¼ûÊÚȨ¡£
¹ØÓÚÐèÒª»ñÈ¡ÌØ¶¨¹¦Ð§µÄÓû§¶øÑÔ£¬Ê®´óÃâ·Ñ»ÆÈí¼þÏÂÔØ¹Ù·½°²×¿°æV92.3.4°æ±¾È·ÊµÌṩÁËÊÖÒÕ½â¾ö¼Æ»®£¬µ«±ØÐ轨ÉèÔÚÑÏ¿á×ñÊØÍøÂçÇå¾²¹æ·¶µÄ»ù´¡Ö®ÉÏ¡£½¨ÒéÓû§ÓÅÏÈÑ¡Ôñ¾ÓÉEV´úÂëÊðÃûÈÏÖ¤µÄ×°ÖÃÔ´£¬ÅäºÏϵͳ¼¶·À»¤¹¤¾ß¹¹½¨È«·½Î»Çå¾²ÆÁÕÏ¡£Ëæ×ÅÒÆ¶¯Éú̬Çå¾²±ê×¼Ò»Á¬Éý¼¶£¬¼æ¹Ë¹¦Ð§ÐèÇóÓëÒþ˽±£»¤µÄÊÖÒռƻ®½«³ÉΪÐÐÒµÖ÷Á÷Éú³¤Æ«Ïò¡£