FB pixel

Touch ID returns for new iPhone SE as OnePlus fingerprint biometric vulnerability found and patched

 

Fingerprint-Identification

Even a deadly pandemic has not prevented Apple from launching a new iPhone, the second-generation iPhone SE, which includes Touch ID fingerprint biometrics integrated with a front-mounted home button instead of Face ID facial recognition.

The new smartphone retails for a suggested $399, and features an A13 Bionic chip, which is used in other iPhones and the company calls the fastest in such a device, and a 4.7-inch Retina HD display, which is among the smallest Apple has released.

There are few differences between the appearance of the iPhone SE and an iPhone 8, the Wall Street Journal writes.

The iPhone SE includes a rear camera with high-quality video capture, according to the company’s announcement, but the Journal reports it has generally more modest camera specifications than higher-end iPhones.

According to the Journal, a new line of iPhones slated for a fall release will feature a new design and 5G connectivity.

OnePlus biometric data vulnerability reported

OnePlus 7 Pro Android phones have a vulnerability which allows an attacker with root privileges to exfiltrate bitmap fingerprint images from the device’s Trusted Execution Environment (TEE), according to a blog post from the Synopsys Cybersecurity Research Center’s (CyRC).

Vulnerability CVE-2020-7958 makes images from the fingerprint sensor of the OnePlus 7, which should only be accessible in the TEE, available from the Rich Execution Environment (REE). The vulnerability has a CVSS 3.0 overall score of 6.6, which places it near the high end of the medium severity rating.

An attacker gaining root privileges in the REE can communicate directly with factory testing APIs exposed by Trusted Applications running in the TEE, CyRC explains, enabling a sequence of commands to expose the biometric data.

OnePlus addressed the vulnerability with the 10.0.3.GM21BA software build, which all users should update their devices to.

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

AI agents operating continuously at machine speed are breaking human-centric IAM

New research commissioned by Ping Identity and compiled by KuppingerCole Analysts shows that “agents are being deployed into production faster…

 

Criticism follows inclusion of Madras Security Printers in Sri Lanka digital ID bids

Civil society group the People’s Struggle Alliance (PSA) has raised concerns regarding the inclusion of Madras Security Printers (MSP) in…

 

Malaysia’s MyDigital ID adds 29 partners as adoption grows

Twenty-nine organizations have joined MyDigital ID, the Malaysian government’s decentralized digital ID system, in what a report calls “a significant…

 

authID looks to raise $4M in private placement as challenging transition continues

authID is looking to raise $4 million less expenses in bridge loan financing for “working capital and general corporate purposes.”…

 

Checkr launches sharable profiles, integrates Socure into Checkr Trust

Biometric background check provider Checkr has launched Checkr Profiles for verified credentials. According to a release, the product allows individuals…

 

Germany launches program to bring open source maintainers into standards bodies

Tech experts who lead open source digital infrastructure projects rarely get to participate in developing technical standards, even though three-quarters…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events