Beautiful Virgin Islands

Sunday, Nov 23, 2025

Apple Fixes One of the iPhone's Most Pressing Security Risks

Apple Fixes One of the iPhone's Most Pressing Security Risks

By hardening iMessage in iOS 14, the company has effectively cut off what had been an increasingly popular line of attack.
Apple's iOS operating system is generally considered secure, certainly enough for most users most of the time. But in recent years hackers have successfully found a number of flaws that provide entry points into iPhones and iPads. Many of these have been what are called zero-click or interactionless attacks that can infect a device without the victim so much as clicking a link or downloading a malware-laced file.

Time and again these weaponized vulnerabilities turned out to be in Apple's chat app, iMessage. But now it appears that Apple has had enough. New research shows that the company took iMessage's defenses to a whole other level with the release of iOS 14 in September.

At the end of December, for example, researchers from the University of Toronto’s Citizen Lab published findings on a hacking campaign from the summer in which attackers successfully targeted dozens of Al Jazeera journalists with a zero-click iMessages attack to install NSO Group's notorious Pegasus spyware. Citizen Lab said at the time that it didn't believe iOS 14 was vulnerable to the hacking used in the campaign; all the victims were running iOS 13, which was current at the time.

Samuel Groß has long investigated zero-click iPhone attacks alongside a number of his colleagues at Google's Project Zero bug-hunting team. The week, he detailed three improvements that Apple added to iMessage to harden the system and make it much more difficult for attackers to send malicious messages crafted to wreak strategic havoc.

“These changes are probably very close to the best that could’ve been done given the need for backward compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole,” Groß wrote on Thursday. “It’s great to see Apple putting aside the resources for these kinds of large refactorings to improve end users’ security.”

In response to Citizen Lab's research, Apple said in December that “iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks.”

iMessage is an obvious target for zero-click attacks for two reasons. First, it's a communication system, meaning part of its function is to exchange data with other devices. iMessage is literally built for interactionless activity; you don't need to tap anything to receive a text or photo from a contact. And iMessage's full suite of features—integrations with other apps, payment functionality, even small things like stickers and memoji—make it fertile ground for hackers as well. All those interconnections and options are convenient for users but add “attack surface,” or potential for weakness.

“iMessage is a built-in service on every iPhone, so it’s a huge target for sophisticated hackers,” says Johns Hopkins cryptographer Matthew Green. “It also has a ton of bells and whistles, and every single one of those features is a new opportunity for hackers to find bugs that let them take control of your phone. So what this research shows is that Apple knows this and has been quietly hardening the system.”

Groß outlines three new protections Apple developed to deal with its iMessage security issues at a structural level, rather than through Band-Aid patches. The first improvement, dubbed BlastDoor, is a “sandbox,” essentially a quarantine zone where iMessage can inspect incoming communications for potentially malicious attributes before releasing them into the main iOS environment.

The second new mechanism monitors for attacks that manipulate a shared cache of system libraries. The cache changes addresses within the system at random to make it harder to access maliciously. iOS only changes the address of the shared cache after a reboot, though, which has given zero-click attackers an opportunity to discover its location; it's like taking shots in the dark until you hit something. The new protection is set up to detect malicious activity and trigger a refresh without the user having to restart their iPhone.

The final addition makes it more difficult for hackers to “brute force,” or retry attacks multiple times—a common technique in zero-click hacks if an assault doesn't quite work the first time. This protection is relevant to reducing those shots in the dark to find the shared cache, but also to attacks more broadly, like attempts to send multiple malicious texts (which are typically invisible to the user) to retry an attack until it works.

Independent researchers agree with Groß's assessment that the version of iMessage in iOS 14 is much better defended against these types of attacks.

“The mitigations are very welcome and appear to be intelligently done,” says Will Strafach, a longtime iOS researcher and creator of the Guardian Firewall app for iOS. “I would have hoped to see something like this sooner as iMessage is a big target for remote attacks, but it at least looks like they put a decent amount of care into this.”

Now that they're here, the improvements should make a big difference in curbing the rising tide of interactionless attacks against iMessage. But researchers warn that it's only a matter of time before attackers find a new spin on their stalwart techniques.
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Johnson Blasts ‘Incoherent’ Covid Inquiry Findings Amid Report’s Harsh Critique of His Government
Lord Rothermere Secures £500 Million Deal to Acquire Telegraph Titles
Maduro Tightens Security Measures as U.S. Strike Threat Intensifies
U.S. Envoys Deliver Ultimatum to Ukraine: Sign Peace Deal by Thursday or Risk Losing American Support
Zelenskyy Signals Progress Toward Ending the War: ‘One of the Hardest Moments in History’ (end of his business model?)
U.S. Issues Alert Declaring Venezuelan Airspace a Hazard Due to Escalating Security Conditions
The U.S. State Department Announces That Mass Migration Constitutes an Existential Threat to Western Civilization and Undermines the Stability of Key American Allies
Students Challenge AI-Driven Teaching at University of Staffordshire
Pikeville Medical Center Partners with UK’s Golisano Children’s Network to Expand Pediatric Care
Germany, France and UK Confirm Full Support for Ukraine in US-Backed Security Plan
UK Low-Traffic Neighbourhoods Face Rising Backlash as Pandemic Schemes Unravel
UK Records Coldest Night of Autumn as Sub-Zero Conditions Sweep the Country
UK at Risk of Losing International Doctors as Workforce Exodus Grows, Regulator Warns
ASU Launches ASU London, Extending Its Innovation Brand to the UK Education Market
UK Prime Minister Keir Starmer to Visit China in January as Diplomatic Reset Accelerates
Google Launches Voluntary Buyouts for UK Staff Amid AI-Driven Company Realignment
UK braces for freezing snap as snow and ice warnings escalate
Majority of UK Novelists Fear AI Could Displace Their Work, Cambridge Study Finds
UK's Carrier Strike Group Achieves Full Operational Capability During NATO Drill in Mediterranean
Trump and Mamdani to Meet at the White House: “The Communist Asked”
Nvidia Again Beats Forecasts, Shares Jump in After-Hours Trading
Wintry Conditions Persist Along UK Coasts After Up to Seven Centimetres of Snow
UK Inflation Eases to 3.6 % in October, Opening Door for Rate Cut
UK Accelerates Munitions Factory Build-Out to Reinforce Warfighting Readiness
UK Consumer Optimism Plunges Ahead of November Budget
A Decade of Innovation Stagnation at Apple: The Cook Era Critique
Caribbean Reparations Commission Seeks ‘Mutually Beneficial’ Justice from UK
EU Insists UK Must Contribute Financially for Access to Electricity Market and Broader Ties
UK to Outlaw Live-Event Ticket Resales Above Face Value
President Donald Trump Hosts Saudi Crown Prince Mohammed bin Salman at White House to Seal Major Defence and Investment Deals
German Entertainment Icons Alice and Ellen Kessler Die Together at Age 89
UK Unveils Sweeping Asylum Reforms with 20-Year Settlement Wait and Conditional Status
UK Orders Twitter Hacker to Repay £4.1 Million Following 2020 High-Profile Breach
Popeyes UK Eyes Century Mark as Fried-Chicken Chain Accelerates Roll-out
Two-thirds of UK nurses report working while unwell amid staffing crisis
Britain to Reform Human-Rights Laws in Sweeping Asylum Policy Overhaul
Nearly Half of Job Losses Under Labour Government Affect UK Youth
UK Chancellor Reeves Eyes High-Value Home Levy in Budget to Raise Tens of Billions
UK Urges Poland to Choose Swedish Submarines in Multi-Billion € Defence Bid
US Border Czar Tom Homan Declares UK No Longer a ‘Friend’ Amid Intelligence Rift
UK Announces Reversal of Income Tax Hike Plans Ahead of Budget
Starmer Faces Mounting Turmoil as Leaked Briefings Ignite Leadership Plot Rumours
UK Commentator Sami Hamdi Returns Home After US Visa Revocation and Detention
UK Eyes Denmark-Style Asylum Rules in Major Migration Shift
UK Signals Intelligence Freeze Amid US Maritime Drug-Strike Campaign
TikTok Awards UK & Ireland 2025 Celebrates Top Creators Including Max Klymenko as Creator of the Year
UK Growth Nearly Stalls at 0.1% in Q3 as Cyberattack Halts Car Production
Apple Denied Permission to Appeal UK App Store Ruling, Faces Over £1bn Liability
UK Chooses Wylfa for First Small Modular Reactors, Drawing Sharp U.S. Objection
Starmer Faces Growing Labour Backlash as Briefing Sparks Authority Crisis
×