Google discovered that for two years thousands of iPhones have been indiscriminately hacked. Someone has exploited a large number of iPhone vulnerabilities without restraint or careful targeting.
On Thursday evening, Google’s Project Zero security research team publicly revealed a broad campaign of iPhone hacking. They highlight five “exploit chains” which have allowed hackers to penetrate each layer of iOS digital protections. The rare and intricate chains of code took advantage of a total of 14 security flaws. All users of iPhone versions from iOS 10 to iOS 12 were potentially vulnerable. The hack simply required users to visit a website, which has been active since at least 2017, and had thousands of visitors per week.
Once the iPhone had been made vulnerable hackers had access to everything from the browser’s sandbox isolation mechanism to the core of the operating system known as the kernel, ultimately gaining complete control over the phone. Once installed, it could monitor live location data, access photos and contacts, read certain messages for example WhatsApp and iMessages, and gain passwords or other sensitive information from the iOS Keychain. This is a serious vulnerability, of which users were completely unaware.
This is potentially the biggest iPhone hacking incident that has ever been reported. Apple has so far declined to comment on these findings. Security vulnerabilities were reported to them by Google on February 1, which Apple amended in the iOS 12.1.4 update released on February 7. Google has just publicly released this information, which could be timed to clash with Apple’s annual launch event which this year is happening on 10 September, and is suspected to include new iPhone models.
Previously it was believed such hacks were very expensive and therefore targeted. This incident has upturned these beliefs and changed these assumptions. There is not much that can be done in terms of prevention, however, users should be conscious that mass exploitation can still exist. Smartphones should be treated as devices which are vulnerable to attack and which can be compromised. It’s been shown hackers can get access to extremely personal information, and so users should keep this in mind when deciding what information to put on their devices.
