Those who want to jump the gun can go into the phone settings, click "General" then "Software Update," and trigger the patch update directly.Ĭitizen Lab called the iMessage exploit FORCEDENTRY and said it was effective against Apple iOS, MacOS and WatchOS devices. Users should get alerts on their iPhones prompting them to update the phone's iOS software. Apple didn't respond to questions regarding whether this was the first time it had patched a zero-click vulnerability. In a subsequent statement, Apple security chief Ivan Krstić commended Citizen Lab and said such exploits "are not a threat to the overwhelming majority of our users." He noted, as he has in the past, that such exploits typically cost millions of dollars to develop and often have a short shelf life. It said it was aware that the issue may have been exploited and cited Citizen Lab. In a blog post, Apple said it was issuing a security update for iPhones and iPads because a "maliciously crafted" PDF file could lead to them being hacked. He said the malicious file causes devices to crash.Ĭitizen Lab says the case reveals, once again, that NSO Group is allowing its spyware to be used against ordinary civilians. It was discovered during a second examination of the phone, which forensics showed had been infected in March. Malicious image files were transmitted to the activist's phone via the iMessage instant-messaging app before it was hacked with NSO's Pegasus spyware, which opens a phone to eavesdropping and remote data theft, Marczak said. Updated to include speculation that the issue fixed in iOS 14.7.1 was the vulnerability in iMessage being targeted by a zero-click attack to plant Pegasus spyware.World What To Know About The Spying Scandal Linked To Israeli Tech Firm NSOĪlthough security experts say that average iPhone, iPad and Mac user generally need not worry - such attacks tend to be limited to specific targets - the discovery still alarmed security professionals. Updated to include details about the vulnerability fixed in iOS 14.7.1 posted by Saar Amar on Twitter. You know what to do: Don’t wait, update to iOS 14.7.1 now to keep your iPhone safe. The latest upgrade also fixes a bug which meant iPhone models with Touch ID could not unlock a paired Apple Watch using the Unlock with iPhone feature. Wright says there is no need to panic, but “I would highly recommend people update as soon as they can, given there is reason to believe that this is being actively exploited.” The already exploited security vulnerabilities fixed in iOS 14.7.1 make this an important upgrade for your device. For example, Wright advises: “Only install apps from the official App Store and make sure you look at requested permissions-noticing if, for example, a flash light app is requesting access to your contacts-and reading user feedback/reviews.” There could be many reasons for this: Attackers are targeting iPhones more, ethical hackers are finding holes more efficiently, or Apple has more issues with its OS than previously.īut as attackers continue to look for holes to exploit, it’s important to take sensible steps to secure your iPhone. iOS 14.7.1 is the latest in multiple iPhone updatesĪpple’s iOS 14.7.1 is the latest in multiple iPhone updates taking place this year, with Apple seemingly scrambling to patch all the holes appearing in its iOS operating system. There has also been speculation that the issue fixed in iOS 14.7.1 was in fact the zero click attack that targeted iMessage with NSO Group’s Pegasus spyware-but this is not confirmed by Apple.
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |