Thursday, February 2, 2023
No Result
View All Result
NEWSPAPER
The Independent Ghana
28 °c
Accra
  • Home
  • General News
    • News
    • History
    • Features
  • Business
  • Sports
    • Sports
    • FPL
      • Prizes and Rules
  • World
  • Entertainment
    • Showbiz
    • Odd News
    • Lifestyle
  • Independent Africa
  • Scholarships
  • Radio
  • Home
  • General News
    • News
    • History
    • Features
  • Business
  • Sports
    • Sports
    • FPL
      • Prizes and Rules
  • World
  • Entertainment
    • Showbiz
    • Odd News
    • Lifestyle
  • Independent Africa
  • Scholarships
  • Radio
No Result
View All Result
The Independent Ghana
No Result
View All Result
Home World

Google finds ‘indiscriminate iPhone attack lasting years’

August 31, 2019
in World
Google finds ‘indiscriminate iPhone attack lasting years’

The attack affected all models of iPhone, up until the latest version

Share on FacebookShare on Twitter

Security researchers at Google have found evidence of a “sustained effort” to hack iPhones over a period of at least two years.

The attack was said to be carried out using websites which would discreetly implant malicious software to gather contacts, images and other data.

Google’s analysis suggested the booby-trapped websites were said to have been visited thousands of times per week.

Apple told the BBC it did not wish to comment.

The attack was shared in great detail in a series of technical posts written by British cybersecurity expert Ian Beer, a member of Project Zero, Google’s taskforce for finding new security vulnerabilities, known as zero days.

“There was no target discrimination,” Mr Beer wrote.

Read:Google now drives with a ‘Nigerian accent’

“Simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant.”

Mr Beer and his team said they discovered attackers were using 12 separate security flaws in order to compromise devices. Most were bugs within Safari, the default web browser on Apple products.

‘Sustained effort’

Once on a person’s iPhone, the implant could access an enormous amount of data, including (though not limited to) contacts, images and GPS location data. It would relay this information back to an external server every 60 seconds, Mr Beer noted.

The implant also was able to scoop up data from apps a person was using, such as Instagram, WhatsApp and Telegram. Mr Beer’s list of examples also included Google products such as Gmail and Hangouts, the firm’s group video chat app.

Read:EU hits Google with third antitrust fine

The attackers were able to exploit “almost every version from iOS 10 through to the latest version of iOS 12”, Mr Beer added.

“This indicated a group making a sustained effort to hack the users of iPhones in certain communities over a period of at least two years.”

Are you protected?

Apple issued a software fix to address the flaw back in February.

If you are an iPhone user, you should make sure your device is running the latest version of iOS, to make sure you are protected.

To do this, go to Settings and tap General. Under ‘Software Update’ you should be running iOS 12.4.1.

If you are not running iOS 12.4.1 you will be given the opportunity to update your device.

Read:Google outlines $13bn US investment

Apple’s fix

Google’s team notified Apple of the vulnerabilities on 1 February this year. A patch was subsequently released six days later to close the vulnerability. Apple’s patch notes refer to fixing an issue whereby “an application may be able to gain elevated privileges” and “an application may be able to execute arbitrary code with kernel privileges”.

iPhone users should update their device to the latest software to make sure they are adequately protected.

Unlike some security disclosures, which offer merely theoretical uses of vulnerabilities, Google discovered this attack “in the wild” – in other words, it was in use by cybercriminals.

Mr Beer’s analysis did not speculate on who may be behind the attack, nor how lucrative the tool may have been on the black market. Some “zero day” attacks can be sold for several millions dollars – until they’re discovered and fixed.

Source: bbc.com

Tags: Google

Recommended

Shisha is more dangerous than cigarettes – Dr. Blaise Ackom warns

Shisha is more dangerous than cigarettes – Dr. Blaise Ackom warns

February 2, 2023
Military personnel save NEDCo employees detained for cutting off UDS’s power supply

Military personnel save NEDCo employees detained for cutting off UDS’s power supply

February 2, 2023

Popular News

    The Independent Ghana

    © 2023 The Independent Ghana

    Navigate Site

    • Home
    • About Us
    • Contact Us
    • FPL
    • Privacy Policy
    • Lifestyle
    • Students & Scholarships

    Follow Us

    No Result
    View All Result
    • Home
    • General News
      • News
      • History
      • Features
    • Business
    • Sports
      • Sports
      • FPL
        • Prizes and Rules
    • World
    • Entertainment
      • Showbiz
      • Odd News
      • Lifestyle
    • Independent Africa
    • Scholarships
    • Radio

    © 2023 The Independent Ghana

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist