Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      South Africa tables Starlink-friendly policy shift

      23 May 2025

      Computex 2025 – key takeaways from Asia’s biggest AI tech show

      23 May 2025

      Iqbal Survé’s Sekunjalo moves to delist controversial Ayo Technology

      23 May 2025

      US banks exploring launch of jointly developed stablecoin

      23 May 2025

      Apple smart glasses could be here next year

      23 May 2025
    • World

      iPhone designer Jony Ive to build AI devices with OpenAI

      22 May 2025

      First AI-generated drugs could go on sale by 2030

      22 May 2025

      Google, Volvo deepen partnership on car software

      21 May 2025

      Microsoft pushes for industry standards in AI agent collaboration

      19 May 2025

      Microsoft to lay off 3% of workforce in organisation-wide cuts

      14 May 2025
    • In-depth

      Sam Altman and Jony Ive’s big bet to out-Apple Apple

      22 May 2025

      South Africa unveils big state digital reform programme

      12 May 2025

      Is this the end of Google Search as we know it?

      12 May 2025

      Social media’s Big Tobacco moment is coming

      13 April 2025

      This is Europe’s shot to emerge from Silicon Valley’s shadow

      10 April 2025
    • TCS

      TCS | Reserve Bank fintech head Lyle Horsley on the G20 TechSprint

      22 May 2025

      TCS+ | Schneider Electric’s Clive Roberts on driving digitisation in the CPG sector

      22 May 2025

      TCS | Dalene Steyn on Capitec’s ambitious mobile gameplan

      21 May 2025

      Meet the CIO | Schalk Visser on Cell C’s big tech pivot

      13 May 2025

      TCS | Kiaan Pillay on fintech start-up Stitch and its R1-billion funding round

      7 May 2025
    • Opinion

      Solar panic? The truth about SSEG, fines and municipal rules

      14 April 2025

      Data protection must be crypto industry’s top priority

      9 April 2025

      ICT distributors must embrace innovation or risk irrelevance

      9 April 2025

      South Africa unprepared for deepfake chaos

      3 April 2025

      Google: South African media plan threatens investment

      3 April 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SkyWire
      • Solid8 Technologies
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Information security » Update your iPhone and Mac now: Serious security flaw uncovered

    Update your iPhone and Mac now: Serious security flaw uncovered

    By Agency Staff14 September 2021
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    A cybersurveillance company in Israel developed a tool to break into Apple iPhones with a never-before-seen technique that has been in use since at least February, Internet security watchdog group Citizen Lab said.

    The discovery is important because of the critical nature of the vulnerability, which requires no user interaction and affects all versions of Apple’s iOS, macOS and watchOS, except for those updated on Monday.

    The tool developed by the Israeli firm, named NSO Group, defeats security systems designed by Apple in recent years. Apple said it fixed the vulnerability in Monday’s software update, confirming Citizen Lab’s finding.

    Apple rapidly developed and deployed a fix in iOS 14.8 to protect our users

    “After identifying the vulnerability used by this exploit for iMessage, Apple rapidly developed and deployed a fix in iOS 14.8 to protect our users,” said Ivan Krstić, head of Apple Security Engineering and Architecture, in a statement. “Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals.

    “While that means they are not a threat to the overwhelming majority of our users, we continue to work tirelessly to defend all our customers, and we are constantly adding new protections for their devices and data,” he added.

    Spyware

    An Apple spokesman declined to comment on whether the hacking technique came from NSO Group.

    In a statement, NSO did not confirm or deny that it was behind the technique, saying only that it would “continue to provide intelligence and law enforcement agencies around the world with life-saving technologies to fight terror and crime”.

    Citizen Lab said it found the malware on the phone of an unnamed Saudi activist and that the phone had been infected with spyware in February. It is unknown how many other users may have been infected.

    The intended targets would not have to click on anything for the attack to work. Researchers said they did not believe there would be any visible indication that a hack had occurred.

    Popular chat apps are at risk of becoming the soft underbelly of device security. Securing them should be top priority

    The vulnerability lies in how iMessage automatically renders images. iMessage has been repeatedly targeted by NSO and other cyber arms dealers, prompting Apple to update its architecture. But that upgrade has not fully protected the system.

    “Popular chat apps are at risk of becoming the soft underbelly of device security. Securing them should be top priority,” said Citizen Lab researcher John Scott-Railton.

    Citizen Lab said multiple details in the malware overlapped with prior attacks by NSO, including some that were never publicly reported. One process within the hack’s code was named “setframed”, the same name given in a 2020 infection of a device used by a journalist at Al Jazeera, the researchers found.

    “The security of devices is increasingly challenged by attackers,” said Citizen Lab researcher Bill Marczak.

    A record number of previously unknown attack methods, which can be sold for US$1-million or more, have been revealed this year. The attacks are labelled “zero-day” because software companies had zero days’ notice of the problem.

    Along with a surge in ransomware attacks against critical infrastructure, the explosion in such attacks has stoked a new focus on cybersecurity in the White House as well as renewed calls for regulation and international agreements to rein in malicious hacking.

    The FBI has been investigating NSO, and Israel has set up a senior interministerial team to assess allegations that its spyware has been abused on a global scale.

    Although NSO has said it vets the governments it sells to, its Pegasus spyware has been found on the phones of activists, journalists and opposition politicians in countries with poor human rights records.  — Reported by Christopher Bing and Joseph Menn, (c) 2021 Reuters



    Apple Citizen Lab NSO Group
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleHow technology is transforming the customer experience in SA
    Next Article China aims for ‘civilised’ Internet with focus on ‘socialist values’

    Related Posts

    Apple smart glasses could be here next year

    23 May 2025

    iPhone designer Jony Ive to build AI devices with OpenAI

    22 May 2025

    Trump tells Tim Cook: stop building iPhone plants in India

    15 May 2025
    Company News

    Kredete launches Africa’s first stablecoin-backed credit card

    23 May 2025

    Surface Copilot+ PCs for business: the future of work, powered by AI

    23 May 2025

    Turbocharge your business operations with a fibre internet line

    23 May 2025
    Opinion

    Solar panic? The truth about SSEG, fines and municipal rules

    14 April 2025

    Data protection must be crypto industry’s top priority

    9 April 2025

    ICT distributors must embrace innovation or risk irrelevance

    9 April 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.