Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Your Apple iPhone had been vulnerable to hackers since iOS 7
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Your Apple iPhone had been vulnerable to hackers since iOS 7

Your Apple iPhone had been vulnerable to hackers since iOS 7

Sheldon Pinto • August 29, 2016, 10:44:05 IST
Whatsapp Facebook Twitter

What is shocking that Government organisations have been using the same for years.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Your Apple iPhone had been vulnerable to hackers since iOS 7

Yes, it had been, until Apple decided to plug it a few days ago in what turned out to be an essential security patch that the Cupertino giant prepared in just 10 days. If you have been glancing through articles in the past days, let me put things down in perspective for you. Yes, your iPhone is vulnerable if it has not been updated iOS 9.3.5 and secondly it has been since iOS 7. This is all thanks to well-protected secret that nobody was aware of until an a 46-year-old human rights activist from the United Arab Emirates, received a strange text message from a number he did not recognise on his iPhone. The bait [caption id=“attachment_332141” align=“aligncenter” width=“640”] ![Image: Ahmed Mansoor, Citizenlab](http://tech.firstpost.com/wp-content/uploads/2016/08/Image-Ahmed-Mansoor-SMS-Citizenlab-Apple-iPhone.jpg) Image: Ahmed Mansoor, Citizenlab[/caption] Had Ahmed Mansoor clicked on the link sent in via SMS (or iMessage), nothing would have been revealed and the company that provides the malware called Pegasus, would have continued to do its business undercover like it has been for a couple of years now. But malware attacks where not new to Mansoor. As reported by Motherboard, the UAE national has already been the victim of government hackers who have used spyware products from companies like FinFisher and Hacking Team. Instead, Mansoor decided to forward that same message to Bill Marczak, a researcher at Citizen Lab, a digital rights watchdog at the University of Toronto’s Munk School of Global Affairs. The chase Marzack along with Scott-Railton got on the job and confirmed the same. But the chase did not end with that. Both researchers followed the online trail tracing it to a server and an IP address that were earlier categorized in their database under Stealth Falcon, a hacking group. Soon enough they also found a server registered to an NSO employee who pointed to the same IP address. That company was the NSO Group and it had been dishing out copies of a sophisticated malware with a three-pronged approach that utilises three different unknown vulnerabilities in Apple’s iOS. Oddly, these were a well kept secret and have never been reported in the past. Citizenlab soon contacted Lookout Security to take a deep dive. How “bad” is bad? Deeper into their research the companies concluded, that the spyware would use three known bugs, better known as zero-days in the iPhone and tagged it as the ‘Trident’. The first bug called CVE-2016-4657 is an exploit for WebKit, which allows execution of the initial shellcode. The second attack comes from a Kernel Address Space Layout Randomization (KASLR) bypass exploit to find the base address of the kernel. And once that is accomplished we have 32 and 64 bit iOS kernel exploits that allow execution of code in the kernel, used to jailbreak the phone and allow software installation. [caption id=“attachment_332120” align=“aligncenter” width=“506”] ![Image: Citizenlab](http://tech.firstpost.com/wp-content/uploads/2016/08/Apple-iPhone-Pegasus-NSO-Group-Citizenlab.png) Image: Citizenlab[/caption] So what can hackers do once all three have been executed (a process that barely takes a few second once the victim clicks on the link)? Well, researchers that malware can intercept “all data” inside of an iPhone. This would include full access to the phone’s files, messages, microphone and video camera, the operator is able to turn the device into a silent digital spy in the target’s pocket. Not impressed? Well, it can also check for calls made by the phone, WhatsApp, and Viber, SMS and data from apps like Gmail, WhatsApp, Skype, Facebook, KakaoTalk, Telegram, and others. It also had access to “A wide range of personal data, such as calendar data and contact lists, as well as passwords, including Wi-Fi passwords.” It’s almost like a spy in your pocket, in the most personal device you have ever owned. Impressed? There’s something bigger to add to this mess. Lookout Security pointed out that “spyware has been in the wild for a significant amount of time based on some of the indicators within the code (e.g., a kernel mapping table that has values all the way back to iOS 7).” A well-funded malware While Apple has finally fixed the Pegasus malware. What is shocking is that government organisations have been using the same for years. It has been used to target activists and the product has been sold in Mexico and Panama in the past. The NSO Group which operates from Israel was formed in 2010. In 2014, US private equity fund Francisco Partners acquired a majority stake in NSO for around $120 million. Soon enough Francisco was searching for a sale of the company that in 2015 was valued at around $1 billion. In the same year, Reuters had earlier pointed out that the NSO Group had an annual revenue of approximately $75 million!

Tags
Apple iOS Malware Spyware Apple iPhone Trident Vulnerabilities iphone hack Lookout Security NSO Group Pegasus malware
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV