Google Outlines iPhone Vulnerabilities That Let Malicious Websites Steal User Data for Years, Now Fixed

Google's Project Zero published a blog post this week about a previous security threat wherein malicious websites quietly hacked into the victim's iPhone. This small collection of hacked websites were used in what was described as "indiscriminate" attacks against unsuspecting visitors for years, but the threat has been addressed by Apple.

iphonexrxsmax
If the attacks were successful, a monitoring implant would be installed on the targeted ‌iPhone‌, able to steal private data including messages, photos, and GPS location in real time. Google estimated that thousands of visitors headed to these websites per week over the course of two years, and that iOS versions ranging from iOS 10 to iOS 12 were exploited.

There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant. We estimate that these sites receive thousands of visitors per week.

TAG was able to collect five separate, complete and unique iPhone exploit chains, covering almost every version from iOS 10 through to the latest version of iOS 12. This indicated a group making a sustained effort to hack the users of iPhones in certain communities over a period of at least two years.

Project Zero discovered exploits for a total of 14 vulnerabilities in iOS, seven for Safari, five for the kernel, and two separate sandbox escapes. The team reported these findings to Apple in February, and Apple's release of iOS 12.1.4 that same month addressed the issues.

Google's deep dive into the iOS exploit can be read on the company's Project Zero blog.

Top Rated Comments

noSpeed Avatar
61 months ago
So what were the malicious sites?
Score: 72 Votes (Like | Disagree)
Expos of 1969 Avatar
61 months ago
The defenders will soon be here trying to explain how Apple was not at fault and that the company is really trying to put privacy priority # 1 (ha...ha...ha).
Score: 29 Votes (Like | Disagree)
realtuner Avatar
61 months ago
Stick that on a billboard
Sure. Along with the time Google discovered a security flaw in Safari and instead of notifying Apple so they could fix it they wrote malware to exploit it so they could keep tracking users.

So the moral of the story is: If Google can somehow embarrass Apple over an exploit they'll release information to the public. If they can use the exploit to their own advantage, they'll keep quiet about it.
Score: 23 Votes (Like | Disagree)
DCIFRTHS Avatar
61 months ago
So what were the malicious sites?
Same question. Read the articles, and didn’t see them listed. Maybe I missed them... I feel google has the responsibility to disclose them.
Score: 18 Votes (Like | Disagree)
TheShadowKnows! Avatar
61 months ago
Kudos to Google's Project Zero in spades.
GOTO: https://googleprojectzero.blogspot.com/2019/08/implant-teardown.html


"... we examined how the attackers gained unsandboxed code execution as root on iPhones. At the end of each chain we saw the attackers calling posix_spawn, passing the path to their implant binary which they dropped in /tmp. This starts the implant running in the background as root. There is no visual indicator on the device that the implant is running. There's no way for a user on iOS to view a process listing, so the implant binary makes no attempt to hide its execution from the system.

The implant is primarily focused on stealing files and uploading live location data. The implant requests commands from a command and control server every 60 seconds.

Before diving into the code let's take a look at some sample data from a test phone running the implant and communicating with a custom command and control server I developed. To be clear, I created this test specifically for the purposes of demonstrating what the implant enabled the attacker to do and the screenshots are from my device. The device here is an iPhone 8 running iOS 12.

The implant has access to all the database files (on the victim’s phone) used by popular end-to-end encryption apps like Whatsapp, Telegram and iMessage. We can see here screenshots of the apps on the left, and on the right the contents of the database files stolen by the implant which contain the unencrypted, plain-text of the messages sent and received using the apps..."
Score: 16 Votes (Like | Disagree)
realtuner Avatar
61 months ago
Sounds like working as intended. Bugs found, reported and fixed in the same month.
This.

Going to quote it simply to counter the inevitable posts saying Apple somehow screwed up....blah....blah....blah.

First off, Apple didn't ignore this exploit for years. They simply didn't know about it. The only reason it went unnoticed for so long is because it wasn't widespread. Once an exploit becomes common it's usually discovered quickly. This is why zero-days are so valuable and often sold to governments or others who can afford to pay a couple million for an exploit. It's also why those same people only use the exploits on targets they consider valuable, because once it's out there it will be discovered and fixed.

Secondly, Apple dealt with it immediately. Google notified Apple on Feb 1st and Apple released a patch on Feb 7th. This is a perfect example of Apple having superior security to Android. Exploits will always exist. Being able to quickly roll out a fix for an exploit is one of the most important methods in dealing with them. Something Android is absolutely horrible at.
Score: 16 Votes (Like | Disagree)

Popular Stories

f 7ba5b5b668dd68b7179a599305cff6b117ef35d1

Apple Announces New iPad Pro With M4 Chip, OLED Display, and More

Tuesday May 7, 2024 7:15 am PDT by
Apple today unveiled redesigned iPad Pro models featuring the M4 chip, Ultra Retina XDR OLED displays, a nano-texture display option, and more. The new iPad Pro offers a considerably thinner design and slightly larger 11- and 13-inch display size options. The 11-inch model is 5.3mm thick and weighs less than a pound, while the 13-inch model is just 5.1mm thick and weighs a quarter pound less ...
5

Apple Event Live Blog: New iPad Pro, iPad Air, and More

Tuesday May 7, 2024 6:33 am PDT by
Apple's "Let Loose" event kicks off today at the unusual time of 7:00 a.m. Pacific Time, and we're expecting to see an iPad-focused event with new iPad Pro and iPad Air models, updated Apple Pencil and Magic Keyboard accessories, and perhaps some other announcements. Apple is providing a live video stream on its website, on YouTube, and in the company's TV app across various platforms. We...
iOS 17 All New Features Thumb

Apple Says iOS 17.5 Coming 'Soon' With These New Features for iPhones

Monday May 6, 2024 7:33 am PDT by
Apple today announced that iOS 17.5 will be released to the public "soon," following over a month of beta testing. While the software update is relatively minor, it does have a few new features and changes, as outlined in the list below. "The new Pride Radiance watch face and iPhone and iPad wallpapers will be available soon with watchOS 10.5, iOS 17.5, and iPadOS 17.5," said Apple, in its...
f 157980180c661f30ff9611287c90241baf30faff

Apple Announces Redesigned Magic Keyboard for New iPad Pro Starting at $299

Tuesday May 7, 2024 7:39 am PDT by
Apple at its "Let Loose" event today announced a new Magic Keyboard for the latest iPad Pro models, with a thinner, lighter design. Apple says the Magic Keyboard has been redesigned to be thinner and lighter, while maintaing the same floating design. Two colors are available that match the new iPad Pro. New features include a function row with screen brightness controls, an aluminum...
maxresdefault

Everything Announced at Today's Apple Event

Tuesday May 7, 2024 1:06 pm PDT by
Apple today held the first event of 2024, debuting new iPad Air and iPad Pro models and accompanying accessories. While the event was faster than normal and took 40 minutes, we've condensed it down even further for those who want a quick overview of everything that was announced. Subscribe to the MacRumors YouTube channel for more videos. We've also got a full recap of all of the coverage...
iPhone 15 Colors yellow

'iPhone 17 Slim' With Smaller Display Rumored to Launch Next Year

Monday May 6, 2024 9:14 am PDT by
While the iPhone 16 series is still months away from launching, an early rumor about an all-new iPhone 17 model has now surfaced. In a research note with investment firm Haitong this week, analyst Jeff Pu said Apple is planning a so-called "iPhone 17 Slim" model that would replace the Plus model in the lineup. Pu said this model will feature around a 6.6-inch display, a slimmer design, an...
Apple iPad Air hero 240507

Apple Announces New M2 iPad Air Models in 11-Inch and 13-Inch Sizes From $599

Tuesday May 7, 2024 7:10 am PDT by
Apple at its "Let Loose" event today announced new M2-powered iPad Air models in 11-inch and 13-inch sizes with a new landscape FaceTime camera, AI features, and better sound quality with the larger model. Apple says the iPad Air has been designed "to make features pioneered on iPad Pro at a more affordable price," with the brand new larger 13-inch model offering 30% more screen real estate ...