Beautiful Virgin Islands

Sunday, Apr 19, 2026

Apple Fixes One of the iPhone's Most Pressing Security Risks

Apple Fixes One of the iPhone's Most Pressing Security Risks

By hardening iMessage in iOS 14, the company has effectively cut off what had been an increasingly popular line of attack.
Apple's iOS operating system is generally considered secure, certainly enough for most users most of the time. But in recent years hackers have successfully found a number of flaws that provide entry points into iPhones and iPads. Many of these have been what are called zero-click or interactionless attacks that can infect a device without the victim so much as clicking a link or downloading a malware-laced file.

Time and again these weaponized vulnerabilities turned out to be in Apple's chat app, iMessage. But now it appears that Apple has had enough. New research shows that the company took iMessage's defenses to a whole other level with the release of iOS 14 in September.

At the end of December, for example, researchers from the University of Toronto’s Citizen Lab published findings on a hacking campaign from the summer in which attackers successfully targeted dozens of Al Jazeera journalists with a zero-click iMessages attack to install NSO Group's notorious Pegasus spyware. Citizen Lab said at the time that it didn't believe iOS 14 was vulnerable to the hacking used in the campaign; all the victims were running iOS 13, which was current at the time.

Samuel Groß has long investigated zero-click iPhone attacks alongside a number of his colleagues at Google's Project Zero bug-hunting team. The week, he detailed three improvements that Apple added to iMessage to harden the system and make it much more difficult for attackers to send malicious messages crafted to wreak strategic havoc.

“These changes are probably very close to the best that could’ve been done given the need for backward compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole,” Groß wrote on Thursday. “It’s great to see Apple putting aside the resources for these kinds of large refactorings to improve end users’ security.”

In response to Citizen Lab's research, Apple said in December that “iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks.”

iMessage is an obvious target for zero-click attacks for two reasons. First, it's a communication system, meaning part of its function is to exchange data with other devices. iMessage is literally built for interactionless activity; you don't need to tap anything to receive a text or photo from a contact. And iMessage's full suite of features—integrations with other apps, payment functionality, even small things like stickers and memoji—make it fertile ground for hackers as well. All those interconnections and options are convenient for users but add “attack surface,” or potential for weakness.

“iMessage is a built-in service on every iPhone, so it’s a huge target for sophisticated hackers,” says Johns Hopkins cryptographer Matthew Green. “It also has a ton of bells and whistles, and every single one of those features is a new opportunity for hackers to find bugs that let them take control of your phone. So what this research shows is that Apple knows this and has been quietly hardening the system.”

Groß outlines three new protections Apple developed to deal with its iMessage security issues at a structural level, rather than through Band-Aid patches. The first improvement, dubbed BlastDoor, is a “sandbox,” essentially a quarantine zone where iMessage can inspect incoming communications for potentially malicious attributes before releasing them into the main iOS environment.

The second new mechanism monitors for attacks that manipulate a shared cache of system libraries. The cache changes addresses within the system at random to make it harder to access maliciously. iOS only changes the address of the shared cache after a reboot, though, which has given zero-click attackers an opportunity to discover its location; it's like taking shots in the dark until you hit something. The new protection is set up to detect malicious activity and trigger a refresh without the user having to restart their iPhone.

The final addition makes it more difficult for hackers to “brute force,” or retry attacks multiple times—a common technique in zero-click hacks if an assault doesn't quite work the first time. This protection is relevant to reducing those shots in the dark to find the shared cache, but also to attacks more broadly, like attempts to send multiple malicious texts (which are typically invisible to the user) to retry an attack until it works.

Independent researchers agree with Groß's assessment that the version of iMessage in iOS 14 is much better defended against these types of attacks.

“The mitigations are very welcome and appear to be intelligently done,” says Will Strafach, a longtime iOS researcher and creator of the Guardian Firewall app for iOS. “I would have hoped to see something like this sooner as iMessage is a big target for remote attacks, but it at least looks like they put a decent amount of care into this.”

Now that they're here, the improvements should make a big difference in curbing the rising tide of interactionless attacks against iMessage. But researchers warn that it's only a matter of time before attackers find a new spin on their stalwart techniques.
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
News Roundup
Microsoft lost 2.5 millions users (French government) to Linux
Privacy Problems in Microsoft Windows OS
News roundup
Péter András Magyar and the Strategic Reset of Hungary
Hungary After the Landslide — A Strategic Reset in Europe
Meghan Markle Plans Exclusive Women-Focused Retreat During Australia Visit
Starmer and Trump Hold Strategic Talks on Securing Strait of Hormuz Amid Rising Tensions
Unofficial Australia Visit by Prince Harry and Meghan Expected to Stir Tensions with Royal Circles
Pipeline Attack Cuts Significant Share of Saudi Arabia’s Oil Export Capacity
UK Stocks Rise on Ceasefire Momentum and Renewed Focus on Diplomacy
UK to Hold Further Strategic Talks on Strait of Hormuz Security
Starmer Voices Frustration as Global Tensions Drive Up UK Energy Costs
UK Students Voice Concern Over Proposal for Automatic Military Draft Registration
Rising Volatility Drives Uncertainty in UK Fuel and Petrol Prices
UK Moves to Deploy ‘Skyhammer’ Anti-Drone System to Strengthen Airspace Defense
New Analysis Explores UK Budget Mechanics in ‘Behind the Blue’ Feature
Man Arrested After Four Die in Channel Crossing Tragedy
UK Tightens Immigration Framework with New Sponsor Rules and Fee Increases
UK Foreign Secretary Highlights Impact of Intensified Strikes in Lebanon
UK Urges Inclusion of Lebanon in US-Iran Ceasefire Framework
UK Stocks Ease as Ceasefire Doubts in Middle East Weigh on Investor Confidence
UK Reassesses Cloud Strategy Amid Criticism Over Limited Support Measures
UK Calls for Full and Toll-Free Access Through Strait of Hormuz Amid Rising Tensions
Starmer Signals Strategic Shift for Britain Amid Escalating Iran-Linked Tensions
UK Issues Firm Warning to Russia Over Covert Underwater Military Activity
OpenAI Halts Stargate UK Project, Casting Uncertainty Over Britain’s AI Expansion Plans
Starmer Voices Frustration Over Global Pressures Driving UK Energy Costs Higher
UK Deploys Military Assets to Protect Undersea Cables From Suspected Russian Threat
Canada Aligns With US, UK and Australia as Europe Prepares Major Digital Border Overhaul
Meghan Markle’s Planned Australia Appearance Sparks Fresh Speculation
Starmer Warns Sustained Effort Needed to Ensure US–Iran Ceasefire Holds
UK to Partner with Shipping Industry to Rebuild Confidence in Strait of Hormuz, Cooper Says
UK Interest Rate Expectations Ease Following US–Iran Ceasefire Agreement
Starmer Signals Major Effort Needed to Fully Reopen Strait of Hormuz During Gulf Visit
UK Fuel Prices Face Ongoing Volatility Amid Global Pressures and Domestic Factors
Kanye West’s Planned Italy Festival Appearance Draws Debate After UK Entry Ban
Smuggling Routes Shift Toward Belgium as Migrant Crossings to UK Evolve
Ceasefire Offers Potential Relief for UK Fuel and Food Prices Amid Ongoing Uncertainty
Iran Conflict Raises Questions Over UK’s Global Influence and Military Preparedness
Senator McConnell Visits Kentucky to Highlight Federal Investment in Local Projects
Kanye West Barred from Entering UK as Legal Grounds Come into Focus
UK Denies Visa to Kanye West After Sponsors Withdraw from Wireless Festival
Trump-Era Forest Service Restructuring Leads to Closure of UK Lab Focused on Kentucky Woodland Health
Foreign Students in the UK Describe Harsh Living Conditions and Financial Pressures
Reform UK Proposes Visa Restrictions on Nations Pursuing Reparations Claims
Public Reaction Divides Over UK Decision to Bar Kanye West
Calls Grow for UK to Review US Base Access Following Concerns Over Escalating Rhetoric
UK Indicates It Will Not Permit Use of Its Bases for Potential US Strikes on Iran’s Energy Infrastructure
UK Prime Minister Defends Decision to Bar Kanye West, Questions Festival Booking
×