Apple patches against alleged NSO Group zero
Full article814 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Apple released its iOS 14.8 update Monday.
Apple released a patch Monday against two security vulnerabilities, one of which the Israeli surveillance company NSO Group has exploited, according to researchers.
The updated iOS software patches against a zero-click exploit that uses iMessage to launch malicious code, which in turn allows NSO Group clients to infiltrate targets — including the phone of a Saudi activist in March, researchers at Citizen Lab said.
The exploit uses a manipulated gif to crash Apple’s image rendering library. It then launches spyware that researchers say shares distinct features with NSO Group’s Pegasus spyware. Researchers have named the exploit “FORCEDENTRY.”
Zero-click exploits prove especially dangerous because they don’t require users to open the malicious message or link for hackers to gain access to your phone.
Researchers are urging Apple Mac, iPhone and Apple Watch users to immediately update their iOS software. The NSO Group exploit was a zero-day, or previously unknown, vulnerability.
It’s just the latest in a number of zero-click exploits against iOS used by NSO Group in recent years. Hackers suspected of working for the governments of Saudi Arabia and the United Arab Emirates breached three dozen devices belonging to Al Jazeera journalists in 2020 using a zero-click iPhone exploit and NSO Group spyware, Citizen Lab reported in December.
While Apple released a security feature in its iOS 14 update to protect against such attacks. researchers at both Citizen Lab and Amnesty Tech found successful zero-click exploits being used to infiltrate phones with iOS 14.6 as recently as July. Citizen Lab reported last month that government hackers used NSO Group zero-click exploits to infiltrate the phones nine Bahraini activists. The Bahrain government denied the claims.
Another vulnerability patched in Monday’s update affected WebKit, the engine Apple uses to display Safari. The vulnerability allowed hackers to use “maliciously crafted web content” to exploit iPhones and iPads that launched the content. Apple attributed the vulnerability to an anonymous researcher. The flaw is the thirteenth vulnerability with WebKit that Apple has addressed this year.
NSO Group declined to comment on the allegations.
“NSO Group will continue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime,” a spokesperson wrote in an email to CyberScoop.
Updated 9/13/21: with comment from NSO Group.
More Scoops
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia…
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Wyden seeks upgraded NSA security guidance on commercial VPN use
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-zero-click-exploit-webkit-iphone/