Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

IOS is secure? Never was. Hackers breached iPhone users data for years

Cybercriminals implanted iPhones with spyware by exploiting a hole in Apple's operating system

Hackers planted spyware on iPhone users' devices over a two-year period by exploiting a vulnerability in the technology's operating systems, Google said Friday.

The bad actors targeted a group of infected websites that, when visited by iPhone users, attacked the devices and in some cases installed malware, according to Ian Beer of Project Zero, a team of Google security analysts that investigates cybercrime.

"There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant. We estimate that these sites receive thousands of visitors per week," Beer wrote in a blog post.

Using the implant, hackers could access Apple customers' data, including their passwords and personal contacts, as well as messages sent through iMessage, WhatsApp, Gmail and Google Hangouts, according to Project Zero researchers.

Almost every version of Apple's iPhone operating system — from iOS 10 through to the latest version of iOS 12 — was vulnerable, he said. Still, it's unclear how many users might have been affected.


Old bug, new hack

The security bugs Beer identified aren't new, but rather were exploited in novel ways.

"Ian shows this is the first time these types of vulnerabilities have been used out on the wide internet, where if the malicious code was present on a certain website that was accessed, the unsuspecting user would be infected, and remain blissfully ignorant of it," said operating system internals researcher Jonathan Levin.

In this case, no user intervention, such as a prompt to click on a link, was required for an iPhone to get inflected.

The scope of the hack suggests it was backed by a nation rather than an individual, Levin said. "It requires a lot of research, and there has to be an endgame motive for this," he told CBS MoneyWatch. "It's possible that those behind the hack targeted a specific demographic or interest groups."

"My personal hunch, because of the level of proficiency and efficacy of the exploits, is that this is not the work of your average hacker," he added.

Neither is there a sure-fire way for users to protect themselves against security breaches, Beer said. "All that users can do is be conscious of the fact that mass exploitation still exists and behave accordingly; treating their mobile devices as both integral to their modern lives, yet also as devices which when compromised, can upload their every action into a database to potentially be used against them."

Google said it reported its findings to Apple in February, after which the tech giant released an updated operating system to fix the flaws.


Android's no safer

While Beer highlights some of the iPhone's vulnerabilities, the attack shouldn't be misread to suggest that Google's Android operating system is safer, Levin said.

"The takeaway shouldn't be, 'I'm going to use Android from now on because it's more secure.' That's far from it," he said. "Similar and/or possibly worse bugs exist in Android and other operating systems as well. Google Project Zero simply chose to highlight iOS this time."

Apple claims to be the most secure operating system, and for good reason. "Apple genuinely invests extreme efforts in securing iOS on multiple layers, down to their proprietary hardware, and in some aspects are still way ahead of Android," Levin said.

AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
EU Seeks ‘Farage Clause’ in Brexit Reset Talks With Britain
Germany Hit by Major Airport Strikes Disrupting European Travel
Russia Deploys Hypersonic Missile in Strike on Ukraine
There is no sovereign immunity for poisoning millions with drugs.
Béla Tarr, Visionary Hungarian Filmmaker, Dies at Seventy After Long Illness
German Intelligence Secretly Intercepted Obama’s Air Force One Communications
The U.S. State Department’s account in Persian: “President Trump is a man of action. If you didn’t know it until now, now you do—do not play games with President Trump.”
President Trump Says United States Will Administer Venezuela Until a Secure Leadership Transition
Delta Force Identified as Unit Behind U.S. Operation That Captured Venezuela’s President
Europe’s Luxury Sanctions Punish Russian Consumers While a Sanctions-Circumvention Industry Thrives
Europe’s Largest Defence Groups Set to Return Nearly Five Billion Dollars to Shareholders in Twenty Twenty-Five
Diamonds Are Powering a New Quantum Revolution
The Battle Over the Internet Explodes: The United States Bars European Officials and Ignites a Diplomatic Crisis
Fine Wine Investors Find Little Cheer in Third Year of Falls
Caviar and Foie Gras? China Is Becoming a Luxury Food Powerhouse
Hackers Are Hiding Malware in Open-Source Tools and IDE Extensions
Traveling to USA? Homeland Security moving toward requiring foreign travelers to share social media history
Trump in Direct Assault: European Leaders Are Weak, Immigration a Disaster. Russia Is Strong and Big — and Will Win
EU Firms Struggle with 3,000-Hour Paperwork Load — While Automakers Fear De Facto 2030 Petrol Car Ban
White House launches ‘Hall of Shame’ site to publicly condemn media outlets for alleged bias
European States Approve First-ever Military-Grade Surveillance Network via ESA
The Ukrainian Sumo Wrestler Who Escaped the War — and Is Captivating Japan
MediaWorld Sold iPad Air for €15 — Then Asked Customers to Return Them or Pay More
Car Parts Leader Warns Europe Faces Heavy Job Losses in ‘Darwinian’ Auto Shake-Out
Families Accuse OpenAI of Enabling ‘AI-Driven Delusions’ After Multiple Suicides
U.S. Envoys Deliver Ultimatum to Ukraine: Sign Peace Deal by Thursday or Risk Losing American Support
The U.S. State Department Announces That Mass Migration Constitutes an Existential Threat to Western Civilization and Undermines the Stability of Key American Allies
A Decade of Innovation Stagnation at Apple: The Cook Era Critique
German Entertainment Icons Alice and Ellen Kessler Die Together at Age 89
AI Researchers Claim Human-Level General Intelligence Is Already Here
Tragedy in Serbia: Coach Mladen Žižović Collapses During Match and Dies at 44
Trump–Putin Budapest Summit Cancelled After Moscow Memo Raises Conditions for Ukraine Talks
Elon Musk Unveils Grokipedia: An AI-Driven Alternative to Wikipedia
Russia’s President Putin Declares Burevestnik Nuclear Cruise Missile Ready for Deployment
US Administration Under President Donald Trump Reportedly Lifts Ban on Ukraine’s Use of Storm Shadow Missiles Against Russia
White House Announces No Imminent Summit Between Trump and Putin
China Presses Netherlands to “properly” Resolve the Nexperia Seizure as Supply Chain Risks Grow
Merz Attacks Migrants, Sparks Uproar, and Refuses to Apologize: “Ask Your Daughters”
Apple Challenges EU Digital Markets Act Crackdown in Landmark Court Battle
Shouting Match at the White House: 'Trump Cursed, Threw Maps, and Told Zelensky – "Putin Will Destroy You"'
‘No Kings’ Protests Inflate Numbers — But History Shows Nations Collapse Without Strong Executive Power
"The Tsunami Is Coming, and It’s Massive": The World’s Richest Man Unveils a New AI Vision
EU Moves to Use Frozen Russian Assets to Buy U.S. Weapons for Ukraine
Europe Emerges as the Biggest Casualty in U.S.-China Rare Earth Rivalry
“Firepower” Promised for Ukraine as NATO Ministers Meet — But U.S. Tomahawks Remain Undecided
The Sydney Sweeney and Jeans Storm: “The Outcome Surpassed Our Wildest Dreams”
Dutch Government Seizes Chipmaker After U.S. Presses for Removal of Chinese CEO
AI and Cybersecurity at Forefront as GITEX Global 2025 Kicks Off in Dubai
Ex-Microsoft Engineer Confirms Famous Windows XP Key Was Leaked Corporate License, Not a Hack
Hungarian Prime Minister Viktor Orbán stated that Hungary will not adopt the euro because the European Union is falling apart.
×