3 years, 6 months ago

Apple patches exploit attributed to Pegasus

Apple released an emergency software patch to fix a security vulnerability that researchers said could allow hackers to directly infect Apple devices without any user action. The researchers at the University of Toronto’s Citizen Lab said the flaw allowed Pegasus spyware from the world’s most infamous hacker-for-hire firm, NSO Group, to directly infect the iPhone of a Saudi activist. Although Citizen Lab previously found evidence of zero-click exploits being used to hack into the phones of al-Jazeera journalists and other targets, “this is the first one where the exploit has been captured so we can find out how it works,” said Mr. Marczak. A malicious image file was transmitted to the activist’s phone via the iMessage instant-messaging app before it was hacked with NSO’s Pegasus spyware, which opens a phone to eavesdropping and remote data theft, Mr. Marczak said.

The Hindu

Discover Related