web analytics

New Zero-Click Exploits Against iOS

Rate this post

HomeBlog

New Zero-Click Exploits Against iOS

CitizenLab has identified three zero-click exploits against iOS 15 and 16. These were used by NSO Group’s Pegasus spyware in 2022, and deployed by Mexico against human rights defenders. These vulnerabilities have all been patched.

One interesting bit is that Apple’s Lockdown Mode (part of iOS 16) seems to have worked to prevent infection.

News article.

Posted on April 20, 2023 at 6:47 AM
1 Comments

Comments

TimH


April 20, 2023 9:56 AM

“The first step targets HomeKit, and the second step targets iMessage.”

“the first step targets the iPhone’s Find My feature, and the second step targets iMessage.”

Can Homekit be disabled?


If Find My is disabled, does it still work?


If JS is disabled for Safari (the only place), does it still work?


Atom Feed
Subscribe to comments on this entry

Sidebar photo of Bruce Schneier by Joe MacInnis.

Views: 0

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post

More Latest Published Posts