City
Epaper

Apple fixes zero-day bugs used to deliver Pegasus spyware on iPhones

By IANS | Updated: September 8, 2023 08:30 IST

San Francisco, Sep 8 Apple has fixed two zero-day vulnerabilities actively being used to deliver Israel-based NSO Group’s ...

Open in App

San Francisco, Sep 8 Apple has fixed two zero-day vulnerabilities actively being used to deliver Israel-based NSO Group’s Pegasus spyware on iPhones.

Internet watchdog group Citizen Lab, while checking the device of an individual employed by a Washington DC-based civil society organisation with international offices, found the zero-click vulnerability.

“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab said in a statement late on Thursday.

They refered to the exploit chain as ‘BLASTPASS’. The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim.

Citizen Lab immediately disclosed our findings to Apple and assisted in their investigation.

Apple issued two CVEs related to this exploit chain (CVE-2023-41064 and CVE-2023-41061).

“We would like to acknowledge The Citizen Lab at The University of Torontoʼs Munk School for their assistance,” said the tech giant.

Citizen Lab has urged everyone to immediately update their devices.

“We encourage everyone who may face increased risk because of who they are or what they do to enable Lockdown Mode,” the researchers said.

Apple’s update will secure devices belonging to regular users, companies, and governments around the globe.

“The 'BLASTPASS' discovery highlights the incredible value to our collective cybersecurity of supporting civil society organizations,” said the watchdog.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

InternationalRussia, China veto Hormuz resolution as Trump’s threat looms

Entertainment‘Ramayana’ producer Namit Malhotra reacts to trolling, criticism over film’s VFX, assures better output

NationalBengal polls: Illegal items valued at Rs 327.44 crore seized from Feb 26 to April 6

NationalUttarakhand CM chairs meeting ahead of PM Modi's visit to Uttarakhand

InternationalGor meets US commerce chief ahead of White House dinner with Trump

Technology Realted Stories

TechnologyAdani tells US judge to dismiss SEC fraud suit against him as case 'legally flawed'

TechnologyMaharashtra clears MahaGeoTech, resilience programme

TechnologyClaims of curbing dissent under IT Rules a 'myth': MeitY Secretary

TechnologyMajor cyber fraud busted in Noida, four held for duping foreign nationals

TechnologyFMCG firms should consolidate portfolios, diversify supply chains to counter global risks: Report