For years, the CIA has been developing tools to compromise Apple products, and today thanks to WikiLeaks, we have more information.
Today, the website WikiLeaks published new documents it dubbed “Dark Matter,” adding to its existing Vault 7 that includes information about the hacking tools the CIA develops, purchases, and uses. Today’s documents are specifically focused on Apple products, detailing the methods the CIA uses to “crack” MacBooks and iPhones.
Most of the leaked documents have existed for more than seven years. Thus one might think that the company's current products are probably not at risk. However, despite the age of the documents, the persistent efforts of the secret services to find and exploit vulnerabilities in Apple's products are evident.
One of the tools, called “Sonic Screwdriver,” was used to infect MacBooks via USB or the Thunderbolt port, and for the CIA to operate it must have physical access to a device. Other exploits mentioned by today's leaks are installed in the computer's firmware, making them undetectable by conventional forensic techniques.
The CIA seems to have had the most trouble with early versions of the iPhone. Only one of the tools the agency had targeted the phone. The so-called “beacon” tool is designed to be installed on devices before they hit the market.
Considering how old the bugs are, it is unlikely that any of them still work effectively against modern Apple products.
Of course it is very likely that the CIA has developed new tools that target today's MacBooks and iPhones.
WikiLeaks has pledged to disclose all vulnerabilities reported in Vault 7 to directly affected companies for remediation. It has so far failed to keep its promise, reportedly requiring a series of conditions before disclosing the bugs.
