In what's being touted as potentially one of the biggest attacks on Watch This Ain't Ghostbusters XXX ParodyiPhone users ever, Google has revealed that a collection of websites were hacked to deliver malware onto iPhones, with the iOS vulnerabilities involved going unchecked and undiscovered for years -- as well as subsequent attacks.
The hacks installed zero-interaction malware into unnamed sites that received thousands of visitors every week. Simply visiting the sites, without clicking or scrolling at all, could deliver a monitoring implant onto users' iPhones.
Google demonstrated that the implant could "steal private data like iMessages, photos and GPS location in real-time"; it also had access to users' keychains and password data, as well as database files containing plaintext of messages sent and received in messaging apps such as Google Hangouts, and even end-to-end encrypted apps including WhatsApp, iMessage, and Telegram.
The malware would be wiped if the iPhone was rebooted, but any sensitive information obtained during the infection could still leave the device, its user, and their online life vulnerable to attack.
SEE ALSO: Apple will announce new 'iPhone 11' and 'iPhone 11 Pro' on September 10While the choice of sites appeared designed to target certain communities, the attack was otherwise indiscriminate.
Google's security research initiative Project Zero posted a "very deep dive" detailing the exploits, which their Threat Analysis Group discovered and disclosed to Apple in Feb. 2019.
The team found five "separate, complete and unique" exploit chains using 14 vulnerabilities. Several were zero-day, meaning Apple was unaware of them at the time of Project Zero's discovery; Apple patched these within the seven-day deadline Google gave in iOS 12.1.4, the same Feb. 7 update that patched the infamous Group FaceTime vulnerability.
The exploits date back to iOS 10 and through updates of iOS 12.1.2, encompassing "almost every version" in that timeframe.
This Tweet is currently unavailable. It might be loading or has been removed.
The number of Apple exploits discovered appears to have risen sharply over the past year. At the end of July, Project Zero revealed six zero-interaction security bugs that could be exploited through iMessage, only five of which Apple had managed to patch by the time the Google team revealed them. And in August, news broke of the SQLite vulnerability, as demonstrated at DEFCON 2019 using the iOS Contacts app, as well as the vulnerability to the Bluetooth-based "KNOB" attack that affected every iPhone and iPad.
Mashable has contacted Apple for comment.
Topics Cybersecurity
Previous:No News Is Good News
Yankees catcher Austin Wells goes viral with hilarious breakfast burrito reviewsBest Apple deal: Save $50 on the AirPods Pro 2 at Amazon25 best movies on Netflix to stream nowCollege students can now get free ChatGPT PlusBeats Pill: Get it for $50 off at AmazonBest Google Pixel deal: Save $200 on the Google Pixel 9HP AMD 8GB 512GB Storage Laptop deal: Save $250 at Best BuyTeen safety features rolled out on Instagram and Facebook, including restrictions on going Live'Y2K' review: Kyle Mooney combines 2000s nostalgia and roboBest travel deal: Take 30% off Southwest flightsYankees catcher Austin Wells goes viral with hilarious breakfast burrito reviewsNYT Connections hints and answers for April 7: Tips to solve 'Connections' #666.25 best movies on Netflix to stream nowTikTok ban looms in U.S. Here's the latest.Trade in your old device and plant a tree this Earth MonthNintendo Switch 2 handsNYT mini crossword answers for April 7, 2025Best mesh WiFi deal: Save $150 on the Amazon eero Pro 6EBest security deal: Take 28% off the Google Nest CamBest power station deal: Take $100 off the EcoFlow River 3 14 PC Games for Family Time Fun Save $100 on the Bose QuietComfort headphones Majority of Gen Z would marry an AI, survey says Saturn once again reigns supreme with most moons The 4 best AI image generators of 2025 The Zero Click Internet Hurricane Ian videos and pictures show massive flooding in Fort Myers, Naples, and elsewhere A Chat With Video Game Composer Christopher Tin Nvidia's DLSS Second Take: Metro Exodus Investigation DOOM Eternal PC Graphics Benchmark Raycon Everyday Earbuds deal: 20% off at Amazon Webb telescope zooms into the Cartwheel Galaxy Best Garmin deal: Get $50 off the Garmin Forerunner 165 at Amazon Nintendo Switch 2 supports USB mice, too Save $45 on a year of Spotify when you buy this $99 gift card Best robot vacuum deal: Save $200 on Eufy X10 Pro Omni robot vacuum Anatomy of a Monitor How 3D Game Rendering Works: Anti Gadecki vs. Gauff 2025 livestream: Watch French Open for free Melania Trump welcomes you into the AI audiobook era with new memoir
2.0504s , 10131.0390625 kb
Copyright © 2025 Powered by 【Watch This Ain't Ghostbusters XXX Parody】,Fresh Information Network