Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Apple issues fix for a 'zero-click' flaw that can let Pegasus spyware infect devices
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Apple issues fix for a 'zero-click' flaw that can let Pegasus spyware infect devices

Apple issues fix for a 'zero-click' flaw that can let Pegasus spyware infect devices

Agence France-Presse • September 14, 2021, 09:36:30 IST
Whatsapp Facebook Twitter

Pegasus can be deployed as a ‘zero-click exploit,’ meaning that the spyware can install itself without the victim even clicking a booby-trapped link or file.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Apple issues fix for a 'zero-click' flaw that can let Pegasus spyware infect devices

Apple released a fix Monday for a weakness that can let the spyware at the heart of the Pegasus scandal infect devices without users even clicking on a malicious message or link. The **Pegasus software** from Israeli firm NSO Group has been under intense scrutiny since an international media investigation claimed it was used to spy on the phones of human rights activists, journalists and even heads of state. [caption id=“attachment_9944741” align=“alignnone” width=“1280”]Apple-iPhone-XR-review-1280-720-3 (2) Hours after releasing the fix, Apple said it had “rapidly” developed the update following Citizen Lab’s discovery of the problem.[/caption] Researchers at Citizen Lab, a cybersecurity watchdog organisation in Canada, found the problem while analysing a Saudi activist’s phone that had been compromised with the code. “We determined that the mercenary spyware company NSO Group used the vulnerability to remotely exploit and infect the latest Apple devices with the Pegasus spyware,” Citizen Lab wrote in a post.

Today, September 13th, Apple is releasing an update that patches CVE-2021-30860. We urge everyone to immediately update all Apple devices.

— The Citizen Lab (@citizenlab) September 13, 2021

In March, Citizen Lab examined the activist’s phone and determined it was hacked with Pegasus spyware introduced via iMessage texting and that it didn’t even require the phone’s user to so much as click. Hours after releasing the fix, Apple said it had “rapidly” developed the update following Citizen Lab’s discovery of the problem. “Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals,” the company said. NSO did not dispute Pegasus had prompted the urgent software upgrade, and said in a statement that it would “continue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime.” (Also read:  WhatsApp hack: Pegasus scandal highlights India’s self-destructive lack of oversight over its intelligence services)

No click needed

Pegasus has evolved to become more effective since it was uncovered by Citizen Lab and cyber security firm Lookout five years ago. Pegasus can be deployed as a “zero-click exploit,” meaning that the spyware can install itself without the victim even clicking a booby-trapped link or file, according to Lookout senior manager Hank Schless. “Many apps will automatically create a preview or cache of links in order to improve the user experience,” Schless said. “Pegasus takes advantage of this functionality to silently infect the device.” UN experts recently called for an international moratorium on the sale of surveillance technology until regulations are implemented to protect human rights following an Israeli spyware scandal. An international media investigation reported in July that several governments used the Pegasus malware, created by NSO Group, to spy on activists, journalists and politicians. Pegasus can switch on a phone’s camera or microphone and harvest its data. “It is highly dangerous and irresponsible to allow the surveillance technology and trade sector to operate as a human rights-free zone,” the United Nations human rights experts said in a statement at the time. The statement was signed by three special rapporteurs on rights and a working group on the issue of human rights and transnational corporations and other businesses. Israel’s defense establishment has set up a committee to review NSO’s business, including the process through which export licences are granted. NSO insists its software is intended for use only in fighting terrorism and other crimes, and says it exports to 45 countries. (Also Read:  The Pegasus leak: What you need to know right now )

Tags
Apple iOS Apple event Pegasus cybersecurity NSO Group
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV