Logging system security flaw compromises iCloud, Steam accounts

0
Logging system security flaw compromises iCloud, Steam accounts
A new security flaw has been discovered in a rather popular logging library, which is used widely by apps and services across the internet—online gaming platform Steam by Valve, and Apple's iCloud backup platform.

For a bit of a tech refresher, an app or service's logging system has nothing to do with the actual log-in process of a personal account; rather, it simply creates and keeps logs of all the recently performed activities, which can be referred back to should the app or service crash or experienced any other kind of error.

As Mobile Syrup notes, all network systems employ some sort of a logging utility, and when one such library becomes unfortunately compromised, such a vulnerability can have quite a far-reaching and serious impact on multiple levels.

Recommended For You
The logging library in question is named "Apache Log4j," and is a Java-based logging utility created by the Apache Software Foundation (or ASF).

The vulnerability discovered in Log4j, which first became apparent on Minecraft hosting sites, essentially allows attackers to inject strings of code directly into the library. The vulnerability has been dubbed Log4Shell and, it turns out, isn't difficult to exploit at all. An attacker could simply publish chat messages on a site to trigger it, and then put whatever code they want into the logging library.

Last Friday, Minecraft rolled out a patch to stop further exploits of Log4Shell, but there are many other impacted platforms—such as Steam, one of the most popular online gaming platforms, as well as none other than Apple's own iCloud.

It appears both those platforms remain vulnerable to Log4Shell, although Log4j has since updated its library with a patch that apparently reduces the risk of exploits, although it doesn't entirely eliminate it. And because Log4j is such a widely used logging library for many services, it will likely take some time until all connected devices and accounts are completely safe from Log4Shell.

Get Visible as low as $20/mo for 1 year. Limited time offer with code: FRESHSTART

$20 /mo
$25
$5 off (20%)
Offer Ends 6.1.2026 at 11.59pm ET. New members get $5/mo off the $25/mg Visible plan, $35/mo Visible+ plan, or $45/mo Visible+ Pro plan for the first 12 months. Promo code FRESHSTART required at checkout.
Buy at Visible
Recommended For You
COMMENTS (0)
Latest Discussions
by ECPirate37 • 1
by menooch18 • 2