Apple issues urgent iOS patch as it navigates the spyware arms race – Computerworld



Apple did not specify how the attack is delivered, but SecurityWeek surmised it may have been delivered using the web, email, or messaging apps and that simply previewing the malicious file could have enabled the attack, no click required. The vulnerability impacts a range of Apple devices, including multiple generations of iPad, Macs, and iPhones back to iPhone 11.

A pattern of sophisticated exploits 

We don’t know how this exploit was used. Apple said it learned of the incident thanks to a tip-off from Meta’s product security team. It follows a similar incident in 2025 when a vulnerability in WhatsApp may have been exploited alongside another Apple flaw in zero-click targeted attacks against under 200 people. Meta has not said if this latest flaw was used via WhatsApp but described the discovery as part of its “routine security work.”

This attack is the latest in a long, long line of exploits made against Apple’s systems. Apple’s description of this attack strongly suggests its use in an advanced operation against chosen targets. Subsequent to the patch, blockchain security firm SlowMist suggested it had identified iOS exploitation activity targeting sensitive wallet data, which illustrates the danger of zero-click attacks. In response to the flaw, the US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies three days to apply the patch and told them to conduct forensic tests to see if their systems had been at all compromised as a result of the flaw.



Source link