Apple rushes to block ‘zero-click’ iPhone spyware

120540450 gettyimages 1235056717
World

iPhone smartphones seen displayed on a large screen outside the Apple store on Wangfujing Street in Beijing.

Getty Images

Apple has issued a software patch to block so-called “zero-click” spyware that could infect iPhones and iPads.

Independent researchers identified the flaw, which lets hackers access devices through the iMessage service even if users do not click on a link or file.

The problem affects all of the technology giant’s operating systems, the researchers said.

Apple said it issued the security update in response to a “maliciously crafted” PDF file.

University of Toronto’s Citizen Lab, which first highlighted the issue, had previously found evidence of zero-click spyware, but “this is the first one where the exploit has been captured so we can find out how it works,” said researcher Bill Marczak.

The researchers said that the previously unknown vulnerability affected all major Apple devices, including iPhones, Macs and Apple Watches.

Citizen Lab also said the security issue was exploited to plant spyware on a Saudi activist’s iPhone, adding that it had high confidence that the Israeli hacker-for-hire firm, NSO Group, was behind that attack.

In a statement to the Reuters news agency, NSO did not confirm or deny that it was behind the spyware, saying only that it would “continue to provide intelligence and law enforcement agencies around the world with life-saving technologies to fight terror and crime”.

Security experts have said that although the discovery is significant, most users of Apple devices should not be overly concerned as such attacks are usually highly targeted.

Apple said in a blog post that it had issued the iOS 14.8 and iPadOS 14.8 software patches after it became aware of a report that the flaw “may have been actively exploited”.

The announcement came as the technology giant prepared to unveil new devices at its annual launch event on Tuesday.

The company is expected to reveal new iPhones and updates to its AirPods and Apple Watch.

2px presentational grey line

Analysis by Joe Tidy, Cyber Reporter

Apple’s iMessage is one of the most secure messaging apps in the world but clearly it had a dangerous weakness that a hacking team found and exploited.

The news will embarrass Apple which prides itself on being a secure and safe system.

The revelation is potentially another blow to the reputation of NSO Group which is still reeling from recent accusations of widespread spy hacks on innocent people.

It also highlights once again that no device is fully safe if a determined, well-funded team wants to hack it and is paid enough to do so.

The good advice from all corners is for iOS users to update the security software of their devices as soon as possible to patch up the security hole.

But for the vast majority of users, the risk of being a target of this expensive and highly-skilled hacking, is low.

2px presentational grey line

You may also be interested in:

Products You May Like

Articles You May Like

NYC campus extends remote classes amid Gaza protests
Some prospects may be better off not hearing their names called
100 MPs to stand down at the next election
US Congress close to passing long-awaited Ukraine aid
BBC crew sees people struggling on board migrant boat

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.