Google discovers websites exploiting iPhones, pushing spying implants en masse
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-7286 | Out-of-Bounds Write Local Privilege Escalation in Apple iOS and macOS CVE-2019-7286 is a memory corruption flaw (an out-of-bounds write, CWE-787) in Apple's iOS and macOS that Apple addressed with improved input validation. It is triggered locally: the CVSS vector shows a local attack vector requiring user interaction, and an application that corrupts memory through the flaw may gain elevated privileges with high impact on confidentiality, integrity, and availability. Users running iPhones or iPads on iOS before 12.1.4, or macOS Mojave systems without the 10.14.3 Supplemental Update, are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), which indicates confirmed exploitation in the wild, and EPSS assigns it a 15.6% probability of exploitation within 30 days (97th percentile). No public proof-of-concept is catalogued, but defenders should treat it as actively exploited. Do: Update all iPhones and iPads to iOS 12.1.4 or later and apply the macOS Mojave 10.14.3 Supplemental Update (or a later macOS release) on Macs, per the CISA KEV required action. Inventory for devices that cannot run the fixed versions, restrict untrusted applications on them or retire them, since the flaw allows local apps to gain elevated privileges. Given the KEV listing, treat this as an actively exploited vulnerability and prioritize patching in any KEV-driven remediation program. | 7.8 | 16% | KEV |
| masshundreds of millions of Apple devices affected at the time of disclosure; current count of unpatched legacy devices unknown | |
| CVE-2019-7287 | Out-of-Bounds Write in Apple iOS Allows Kernel-Privilege Code Execution Apple iOS versions prior to 12.1.4 contain a memory corruption flaw — an out-of-bounds write (CWE-787) — which Apple fixed with improved input validation in iOS 12.1.4. Based on the flaw's CVSS scoring (local attack vector, user interaction required), it is triggered when a user opens or runs a malicious application on the device. A successful exploit lets that application execute arbitrary code with kernel privileges, giving the attacker full device control and access to all data on the phone. All Apple iPhones (iPhone OS) running iOS versions before 12.1.4 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), confirming known in-the-wild exploitation; EPSS currently assigns a 4.6% probability of exploitation activity within 30 days (91st percentile), no public proof-of-concept is cataloged, and ransomware use is unknown. Do: Apply Apple's update without delay, per CISA KEV's required action: update all iPhones and iOS devices to iOS 12.1.4 or later. Inventory your fleet for devices still running iOS 12.1.3 or earlier and prioritize patching them; on unpatched legacy devices, avoid opening untrusted applications until updated. Where hardware allows, move older devices off iOS 12 to a currently supported iOS release. | 7.8 | 5% | KEV |
| mass≈hundreds of millions of iPhone devices at time of disclosure (early 2019) |
Full article1,057 words · extracted from helpnetsecurity.com · click to collapse
Unidentified attackers have been compromising websites for nearly three years, equipping them with exploits that would hack visiting iPhones without any user interaction and deliver a stealthy implant capable of collecting much of the sensitive information found on users’ iOS-powered devices.

Indiscriminate compromise
“Earlier this year Google’s Threat Analysis Group (TAG) discovered a small collection of hacked websites. The hacked sites were being used in indiscriminate watering hole attacks against their visitors, using iPhone 0-day,” shared Ian Beer, a researcher with Google’s Project Zero.
“There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant. We estimate that these sites receive thousands of visitors per week.”
Subsequent research revealed the attackers’ use of five unique iPhone exploit chains, using 14 vulnerabilities covering almost every version from iOS 10 through to the latest version of iOS 12, meaning that the attackers made “a sustained effort to hack the users of iPhones in certain communities over a period of at least two years.”

Of the 14 vulnerabilities, seven affected Safari (i.e., WebKit, its browser engine), five the kernel and two allowed sandbox escapes.
“Initial analysis indicated that at least one of the privilege escalation chains was still 0-day and unpatched at the time of discovery (CVE-2019-7287 & CVE-2019-7286). We reported these issues to Apple with a 7-day deadline on 1 Feb 2019, which resulted in the out-of-band release of iOS 12.1.4 on 7 Feb 2019,” Beer noted.
“For many of the exploits it is unclear whether they were originally exploited as 0day or as 1day after a fix had already shipped. It is also unknown how the attackers obtained knowledge of the vulnerabilities in the first place,” Google Project Zero researcher Samuel Groß explained.
“Generally they could have discovered the vulnerabilities themselves or used public exploits released after a fix had shipped. Furthermore, at least for WebKit, it is often possible to extract details of a vulnerability from the public source code repository before the fix has been shipped to users.”
More details about the spying implant
According to the researchers, the implant is primarily focused on stealing files and uploading live location data, and beacons to and requests commands from a C&C server every 60 seconds.
It can access:
- Users’ photos, contacts, location data (GPS)
- The device’s Keychain, which contains credentials, certificates and access tokens (e.g., the Google OAuth token)
- Container directories containing all unencrypted messages sent and received via popular end-to-end encryption apps and mail apps (including Telegram, Gmail, QQMail, Whatsapp, WeChat, and Apple’s own iMessage app).

But, interestingly enough, the implant binary does not persist on the device.
“If the phone is rebooted then the implant will not run until the device is re-exploited when the user visits a compromised site again,” Beer noted.
“Given the breadth of information stolen, the attackers may nevertheless be able to maintain persistent access to various accounts and services by using the stolen authentication tokens from the keychain, even after they lose access to the device.”
Who’s behind this?
The researchers didn’t publicly identify the hacked sites (“watering holes”), which is information that could allow us to make an educated guess about the targets and the attackers.
It seems obvious, though, that the attackers have considerable resources at their disposal and, judging by the capabilities of the spying implant, are not financially motivated. In fact, it all points to a long-standing effort supported by a nation-state.
Rendition Infosec founder (and former NSA hacker) Jake Williams told Wired that these campaigns bear many of the hallmarks of a domestic surveillance operation. Still, the fact that the implant uploads the data without HTTPS encryption and to a server whose address is hardcoded in the binary is unusual for such an effort.
“Contrast that with multiple exploit chains and sandbox escapes and it sure sounds like a group with tons of money to buy exploits and little operational experience,” he noted.
The non-disclosure of watering hole sites’ and C&C server’s IP addresses combined with some of the language in Google’s blog posts has spurred online speculation.
Breadcrumbs in the story say ethnic minority groups in China. Now let’s wonder which ones could these be over the last few years? But C&C servers not disclosed.
— Lukasz Olejnik (@lukOlejnik) August 30, 2019
Current educated guess: Threat actor is a Middle Eastern oppressive government and specifically targets a group (dissidents/opp party/journos) via the unknown low traffic sites (indirectly discriminate). Money blown on exploit kits from talented folks with slapped on homegrown C2
— Aaron Grattafiori (@dyn___) August 30, 2019
All that aside, the most important realization resulting from this discovery is that iPhones are not as secure as generally and widely believed.
“The reality remains that security protections will never eliminate the risk of attack if you’re being targeted,” says Beer, and sometimes this might mean “simply being born in a certain geographic region or being part of a certain ethnic group.”
Users should be conscious of that fact and make risk decisions based on it, he concluded. “Let’s also keep in mind that this was a failure case for the attacker: for this one campaign that we’ve seen, there are almost certainly others that are yet to be seen.”
UPDATE (September 09, 2019, 12:50 a.m. PT):
Apple has disputed Google’s characterization of the attack.
“Google’s post, issued six months after iOS patches were released, creates the false impression of ‘mass exploitation’ to ‘monitor the private activities of entire populations in real time,’ stoking fear among all iPhone users that their devices had been compromised. This was never the case,” the company noted.
The attack was “narrowly focused” and “affected fewer than a dozen websites that focus on content related to the Uighur community.”
Apple also said that all evidence indicates that these website attacks were operational for roughly two months, not two years.
“We fixed the vulnerabilities in question in February — working extremely quickly to resolve the issue just 10 days after we learned about it. When Google approached us, we were already in the process of fixing the exploited bugs.”
Unlike Google, Apple had no qualms saying which was the targeted population.
Also, according to Volexity, there were Uyghur and East Turkistan related websites that targeted Android users, too.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2019/08/30/iphone-mass-hacking/