Security fixes in watchOS 2.0

In addition to the many enhancements, and the ability to run native apps on the  Watch, watchOS 2.0 brings a lot of important security fixes. Even if you are not interested in its other features, this makes it an essential update.

Among others, Apple lists:

  • Apple Pay (stops terminals from extracting some recent transaction information),
  • memory corruption in the handling of audio files (could lead to a crash),
  • updates to certificate trust policy,
  • vulnerability in NSURL,
  • issues in cookies,
  • weak encryption of cache data (could allow someone with physical access to decrypt),
  • cryptographic vulnerability which could reveal the RSA private key,
  • bugs in handling font and text files,
  • a bypass of code signing,
  • bug in handling Disk Images,
  • kernel memory corruption,
  • ICU updated to 55.1,
  • disclosure of kernel memory layout,
  • SQLite updated to 3.8.10.2,

and more.