

New zero-click iMessage Pegasus attack can blast right through iOS 14's security...
source link: https://www.techspot.com/news/90923-new-zero-click-imessage-pegasus-attack-can-blast.html
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

New zero-click iMessage Pegasus attack can blast right through iOS 14's security protections
The exploit has already been used in the wild against Bahraini activists
By Adrian Potoroaca Today 11:41 AMIn context: More than 180 journalists around the world have been targeted by various operators of the Pegasus spyware tool developed by Israeli firm NSO Group. New research reveals that despite the common perception that Apple devices are more secure, there are plenty of vulnerabilities that can be exploited through Pegasus even when running the latest software revision for your device.
Last year, it emerged that Facebook wanted to buy the infamous Pegasus spyware tool in 2017 with the explicit purpose to monitor iPhone and iPad users. Pegasus developer NSO Group refused to sell it for that purpose, as the firm is known for its strict policy of only licensing its tools to governments and government agencies for legitimate use cases pertaining to national security and law enforcement.
Fast forward to today, and a new report from Citizen Lab highlights just how effective Pegasus is even on devices running iOS 14. Security researchers found the tool facilitated a zero-click attack on the iPhones of nine Bahraini activists between June 2020 and February 2021.
(Countries where Pegasus has been used against journalists | Forbidden Stories)
The attack relied on two zero-click iMessage exploits -- meaning no interaction from the user is necessary for the exploits to succeed. One of the exploit chains is called KISMET and was discovered in 2020, while the other is a completely new one that is able to bypass Apple's Blastdoor protections, which is why Citizen Labs called it FORCEDENTRY.
Researchers found the attack was successful against iPhones running an up-to-date version of iOS, and that versions 14.4 and 14.6 are confirmed to be vulnerable to it. What isn't clear at this point is whether the security update in iOS 14.7.1 is meant to offer a fix for this particular exploit. Apple is aware of the issue, however, and the company will introduce more security protections in the upcoming iOS 15 release.
Citizen Lab notes with a "high degree of confidence" that four of the nine activists that were hacked have been targeted by the government of Bahrain, which is said to have been using Pegasus since 2017. One of the activists had previously been hacked with the same tool in 2019.
Recommend
-
15
iPWN — Zero-click iMessage zero-day used to hack the iPhones of 36 journalists Malicious messages installed spyware that recorded audio and pics and stole passwords. ...
-
8
Pegasus affairIsrael Tries to Limit Fallout from the Pegasus Spyware ScandalIsrael has been trying to limit the damage the Pegasus spyware scandal is threatening to do to France-Israel relations. The Moroccan intelligence servic...
-
6
@maxiiJaydev JoshiLerner | Infosec | OSINT
-
8
Pegasus spyware is avoiding Apple’s security protections on iPhone
-
6
Summary While analyzing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware, we discovered a zero-day zero-click exploit against iMessage. The exploit, which we call FORCEDENTRY, tar...
-
7
A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution Posted by Ian Beer & Samuel Groß of Google Project Zero We want to thank Citizen Lab for sharing a sample of the FORCEDENTRY exploit with us...
-
15
Chrome’s new sidebar lets you blast through search resultsChrome’s new sidebar lets you blast through search results / For if you don’t want to deal with going back and forth between the search page and the r...
-
8
Code-to-cloud security: How Palo Alto propels security through a one-click solution
-
2
Friday, 02 June 2023 09:48 Kaspersky targeted through iMessage; Russian FSB ties attack to NSA Featured By
-
1
Security Researchers Latest To Blast UK's Online Safety Bill As Encryption Risk
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK