iPhone has a serious bug that could be used without users knowledge, Google security researchers warn

The bugs could allow attackers to view files or crash devices, the researchers warned.


A serious flaw is present in the iPhone that could be used without its owner’s knowledge, security researchers have warned.

Google staff who were looking for bugs said they found six flaws in Apple’s iMessage text app. And one of them is still yet to be fixed, the researchers warned.

What’s more, the problem is “interactionless”, which means that the user of the iPhone does not need to do anything to allow the exploit to be used.

The bugs could allow attackers to view files or crash devices, the researchers warned.

The bugs were found by Google’s Project Zero programme. That is made up of security analysts who hunt for serious vulnerabilities in various software before hackers find them, providing manufacturers with a 90-day deadline before they make the issue public.

The issues could have been exploited in a number of ways, such as remotely accessing files or crashing devices.

Five of the flaws were patched in the iOS 12.4 update rolled out last week, but the sixth alleged bug remains open, which Google is not disclosing until the deadline is reached.

Natalie Silvanovich, one of the researchers who uncovered the flaws, described them as “interactionless”, meaning they can run without the user having to do anything.

The only way one issue could be fixed on an iPhone was by carrying out a complete reboot and recovery leading to data loss, Ms Silvanovich said in her original report in April.

“For the protection of our customers, Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are generally available,” an Apple spokesman said.

“Keeping your software up to date is one of the most important things you can do to maintain your Apple product’s security.”

Project Zero was formed in 2014 with the aim of reducing the number of people harmed by targeted attacks.

It has previously notified the likes of Microsoft and Facebook about vulnerabilities on their services and platforms.

Source: independent


Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button