Fast company logo
|
advertisement

The hackers could then monitor the iPhone’s location and upload virtually any files from the device–including iMessage and WhatsApp messages.

Google discovered websites that could hack your iPhone just by visiting them

[Photo: You X Ventures/Unsplash]

BY Michael Grothaus1 minute read

Google’s Threat Analysis Group (TAG) has published a blog post detailing a number of exploits in iOS that allowed hacked websites to hack into an iPhone simply if the iPhone visited the site. Once an iPhone did that, malware was installed on the device that allowed the hackers to monitor the iPhone’s live location every 60 seconds as well as upload virtually any files from the iPhone—including iMessage and WhatsApp messages.

TAG says the exploit “may be one of the largest attacks against iPhone users ever.” It reportedly affected iPhones running iOS 10 to iOS 12:

Working with TAG, we discovered exploits for a total of fourteen vulnerabilities across the five exploit chains: seven for the iPhone’s web browser, five for the kernel and two separate sandbox escapes. Initial analysis indicated that at least one of the privilege escalation chains was still 0-day and unpatched at the time of discovery.

There is some good news, however. First, an iPhone user had to visit one of the hacked websites in order for their iPhone to be infected. TAG did not specify which websites were hacked, but their report says the sites received “thousands of visitors per week,” suggesting the sites received relatively minor traffic relative to the number of iPhones in the wild.

Further, even if the malware made it onto an iPhone, when a user restarted their iPhone, the malware would be wiped clean in most instances. Of course, news of any exploits in iOS isn’t good—no matter how few users were impacted. The good news is that Apple acted quickly once TAG alerted them to the exploits. TAG says it contacted Apple about the exploits on February 1, 2019, and Apple fixed all of the exploits just six days later with the release of iOS 12.1.4 on February 7, 2019.

advertisement

Recognize your brand’s excellence by applying to this year’s Brands That Matter Awards before the early-rate deadline, May 3.

CoDesign Newsletter logo
The latest innovations in design brought to you every weekday.
Privacy Policy

ABOUT THE AUTHOR

Michael Grothaus is a novelist and author. He has written for Fast Company since 2013, where he's interviewed some of the tech industry’s most prominent leaders and writes about everything from Apple and artificial intelligence to the effects of technology on individuals and society. More


Explore Topics