HomeSecurityiMessage: Zero-click exploit infects iPhones with spyware

iMessage: Zero-click exploit infects iPhones with spyware

According to Citizen Lab, two zero-days in iMessage fixed by Apple in emergency security updates were actively abused as part of a zero-click exploit chain to deploy the commercial Pegasus on fully updated iPhones.

See also: iMessage exempted from EU law

iMessage

The Pegasus is a highly advanced spyware developed by the NSO Group, a company based in Israel. With the ability to exploit zero-days and infect devices without any user interaction, Pegasus is one of the most powerful and stealthy surveillance tools ever created. Once a device is infected, Pegasus can record conversations, gain access to text messages, hide images, and remotely activate the device's camera and microphone.

Two vulnerabilities, identified as CVE-2023-41064 and CVE-2023-41061, allow attackers to infect a fully updated iPhone running iOS 16.6. The incident occurred at a Washington, D.C.-based civil society organization via malicious images embedded in PassKit.

“We refer to the exploit chain as BLASTPASS. The exploit chain was able to compromise iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab said.

“The exploitation concerned PassKit attachments that contained malicious images sent from an iMessage account by the attacker to the victim.“

Citizen Lab urged Apple customers to update their devices immediately and encouraged those at risk of targeted attacks due to their identity or profession to enable the lock-down feature.

Security researchers from Apple and Citizen Lab discovered vulnerabilities in the Image I/O and Wallet libraries over the past two days.

See also: Reddit: Improves content sharing in iMessage
spyware

CVE-2023-41064 is a buffer overflow that is triggered during processing of images that have been maliciously crafted, while CVE-2023-41061 is a verification issue that exploits unapproved attachments.

Both allow malicious actors to execute arbitrary code on unpatched iPhones and iPads.

Apple addressed the vulnerabilities in macOS Ventura 13.5.2, iOS 16.6.1, iPadOS 16.6.1 and watchOS 9.6.2 with improved logic and memory handling.

The list of affected devices includes:

  • iPhone 8 and later
  • iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
  • Macs running macOS Ventura
  • Apple Watch Series 4 and later

See also: You can now reply to iMessages from a Windows 11 PC

Since the beginning of the year, Apple has fixed a total of 13 zero-days that were exploited to target devices running iOS, macOS, iPadOS, and watchOS, including:

  • two zero-days (CVE-2023-37450 and CVE-2023-38606) in July
  • three zero-days (CVE-2023-32434, CVE-2023-32435 and CVE-2023-32439) in June
  • three more zero-days (CVE-2023-32409, CVE-2023-28204 and CVE-2023-32373) in May
  • two zero-days (CVE-2023-28206 and CVE-2023-28205) in April
  • and another WebKit zero-day (CVE-2023-23529) in February
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS