Update your iPhone now to patch a major 'Pegasus' vulnerability

Apple has released a critical iOS 16 security update for iPhones and iPads to patch a particularly malicious bug that could allow a hacker to take over your device with no action on your part. The "zero-click, zero-day" exploit allows attackers to install NSO Group's Pegasus spyware, which could let them read a target's text messages, listen in on calls, pilfer and transmit images, track their location and more. 

The exploit (referred to as "Blastpass") was first discovered by Citizen Lab, which immediately disclosed it to Apple. It was reportedly used to install Pegasus onto the iPhone of an employee from a Washington DC-based organization. It's capable of compromising devices running the latest 16.6 version of iOS "without any interaction from the victim," the group wrote. 

Apple has released iOS 16.6.1 to counter the vulnerability, stating simply that "a maliciously crafted attachment may result in arbitrary code execution." In addition, Citizen Lab even advised "all at-risk users to consider enabling Lockdown Mode as we believe it blocks the attack." It's believed that the attack involved PassKit (an SDK that allows developers to put Apple Pay in their apps), hence the Blastpass name, along with malicious images sent by iMessage. For obvious reasons, Citizen Lab didn't release any other details. 

Lockdown mode is a recent iOS feature designed to severely restrict the functions of Apple devices and is aimed at a "very small number of users who face grave, targeted threats to their digital security," Apple has stated. The company has faced a number of threats of late, including a vulnerability from February 2023 that "may have been actively exploited," Apple said at the time. 

The exploit also brings Pegasus back into the news, following a ban by the Biden administration earlier this year. Developed by the Israel-based cyber-arms company NSO Group, it created a furor after it was used by multiple nations to spy on journalists, activists and others. In one notorious case, it was reportedly used by Saudi Arabia to spy on journalist Jamal Kashoggi, who was later murdered in Turkey. 

This article originally appeared on Engadget at https://www.engadget.com/update-your-iphone-now-to-patch-a-major-pegasus-vulnerability-114009683.html?src=rss https://www.engadget.com/update-your-iphone-now-to-patch-a-major-pegasus-vulnerability-114009683.html?src=rss
Creato 1y | 8 set 2023, 13:30:22


Accedi per aggiungere un commento

Altri post in questo gruppo

President Trump withdraws the US from the Paris climate agreement (again)

When President Biden took office back in 2021, he issued several

21 gen 2025, 02:10:18 | Engadget
Trump executive order rescinds Biden's AI framework

At a rally following the inauguration ceremonies, President Trump had a desk brought out on stage where he signed a number of executive orders. The first of the evening

21 gen 2025, 02:10:17 | Engadget
Trump delays TikTok ban for at least 75 days via executive order

That didn’t take long. Soon after taking office, President Donald Trump signed a swathe of executive orders. Among them was a temporary pause on the law that

21 gen 2025, 02:10:15 | Engadget
Oscar hopeful 'The Brutalist' used AI during production

The filmmakers behind

20 gen 2025, 23:50:02 | Engadget
The Trump Administration is no longer letting asylum seekers make appointments with the CBP One app

As part of sweeping plans to change immigration in the United States, the Trump Administration has removed functionality from the CBP One app, a US Customs and Border Protection app used by asylum

20 gen 2025, 21:30:27 | Engadget
X adds a dedicated video tab to fill the TikTok void

TikTok bid adieu to its US users over the weekend before

20 gen 2025, 16:50:17 | Engadget
China suggests it’s open to a US deal for TikTok after all

China has provided the strongest indication yet that it’s willing to secure a

20 gen 2025, 16:50:16 | Engadget