Beautiful Virgin Islands

Tuesday, Aug 12, 2025

Apple Fixes One of the iPhone's Most Pressing Security Risks

Apple Fixes One of the iPhone's Most Pressing Security Risks

By hardening iMessage in iOS 14, the company has effectively cut off what had been an increasingly popular line of attack.
Apple's iOS operating system is generally considered secure, certainly enough for most users most of the time. But in recent years hackers have successfully found a number of flaws that provide entry points into iPhones and iPads. Many of these have been what are called zero-click or interactionless attacks that can infect a device without the victim so much as clicking a link or downloading a malware-laced file.

Time and again these weaponized vulnerabilities turned out to be in Apple's chat app, iMessage. But now it appears that Apple has had enough. New research shows that the company took iMessage's defenses to a whole other level with the release of iOS 14 in September.

At the end of December, for example, researchers from the University of Toronto’s Citizen Lab published findings on a hacking campaign from the summer in which attackers successfully targeted dozens of Al Jazeera journalists with a zero-click iMessages attack to install NSO Group's notorious Pegasus spyware. Citizen Lab said at the time that it didn't believe iOS 14 was vulnerable to the hacking used in the campaign; all the victims were running iOS 13, which was current at the time.

Samuel Groß has long investigated zero-click iPhone attacks alongside a number of his colleagues at Google's Project Zero bug-hunting team. The week, he detailed three improvements that Apple added to iMessage to harden the system and make it much more difficult for attackers to send malicious messages crafted to wreak strategic havoc.

“These changes are probably very close to the best that could’ve been done given the need for backward compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole,” Groß wrote on Thursday. “It’s great to see Apple putting aside the resources for these kinds of large refactorings to improve end users’ security.”

In response to Citizen Lab's research, Apple said in December that “iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks.”

iMessage is an obvious target for zero-click attacks for two reasons. First, it's a communication system, meaning part of its function is to exchange data with other devices. iMessage is literally built for interactionless activity; you don't need to tap anything to receive a text or photo from a contact. And iMessage's full suite of features—integrations with other apps, payment functionality, even small things like stickers and memoji—make it fertile ground for hackers as well. All those interconnections and options are convenient for users but add “attack surface,” or potential for weakness.

“iMessage is a built-in service on every iPhone, so it’s a huge target for sophisticated hackers,” says Johns Hopkins cryptographer Matthew Green. “It also has a ton of bells and whistles, and every single one of those features is a new opportunity for hackers to find bugs that let them take control of your phone. So what this research shows is that Apple knows this and has been quietly hardening the system.”

Groß outlines three new protections Apple developed to deal with its iMessage security issues at a structural level, rather than through Band-Aid patches. The first improvement, dubbed BlastDoor, is a “sandbox,” essentially a quarantine zone where iMessage can inspect incoming communications for potentially malicious attributes before releasing them into the main iOS environment.

The second new mechanism monitors for attacks that manipulate a shared cache of system libraries. The cache changes addresses within the system at random to make it harder to access maliciously. iOS only changes the address of the shared cache after a reboot, though, which has given zero-click attackers an opportunity to discover its location; it's like taking shots in the dark until you hit something. The new protection is set up to detect malicious activity and trigger a refresh without the user having to restart their iPhone.

The final addition makes it more difficult for hackers to “brute force,” or retry attacks multiple times—a common technique in zero-click hacks if an assault doesn't quite work the first time. This protection is relevant to reducing those shots in the dark to find the shared cache, but also to attacks more broadly, like attempts to send multiple malicious texts (which are typically invisible to the user) to retry an attack until it works.

Independent researchers agree with Groß's assessment that the version of iMessage in iOS 14 is much better defended against these types of attacks.

“The mitigations are very welcome and appear to be intelligently done,” says Will Strafach, a longtime iOS researcher and creator of the Guardian Firewall app for iOS. “I would have hoped to see something like this sooner as iMessage is a big target for remote attacks, but it at least looks like they put a decent amount of care into this.”

Now that they're here, the improvements should make a big difference in curbing the rising tide of interactionless attacks against iMessage. But researchers warn that it's only a matter of time before attackers find a new spin on their stalwart techniques.
Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Trump Proposes Land Concessions to End Ukraine War
New Road Safety Measures Proposed in the UK: Focus on Eye Tests and Stricter Drink-Driving Limits
Viktor Orbán Criticizes EU's Financial Support for Ukraine Amid Economic Concerns
South Korea's Military Shrinks by 20% Amid Declining Birthrate
US Postal Service Targets Unregulated Vape Distributors in Crackdown
Duluth International Airport Running on Tech Older Than Your Grandmother's Vinyl Player
RFK Jr. Announces HHS Investigation into Big Pharma Incentives to Doctors
Australia to Recognize the State of Palestine at UN Assembly
The Collapse of the Programmer Dream: AI Experts Now the Real High-Earners
Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere
Street justice isn’t pretty but how else do you deal with this kind of insanity? Sometimes someone needs to standup and say something
Armenia and Azerbaijan sign U.S.-brokered accord at White House outlining transit link via southern Armenia
Barcelona Resolves Captaincy Issue with Marc-André ter Stegen
US Justice Department Seeks Release of Epstein and Maxwell Grand Jury Exhibits Amid Legal and Victim Challenges
Trump Urges Intel CEO Lip-Bu Tan to Resign Over Alleged Chinese Business Ties
Scotland’s First Minister Meets Trump Amid Visit Highlighting Whisky Tariffs, Gaza Crisis and Heritage Links
Trump Administration Increases Reward for Arrest of Venezuelan President Maduro to Fifty Million Dollars
Armenia and Azerbaijan to Sign US-Brokered Framework Agreement for Nakhchivan Corridor
British Labour Government Utilizes Counter-Terrorism Tools for Social Media Monitoring Against Legitimate Critics
OpenAI Launches GPT‑5, Its Most Advanced AI Model Yet
Embarrassment in Britain: Homelessness Minister Evicted Tenants and Forced to Resign
President Trump nominated Stephen Miran, his top economic adviser and a critic of the Federal Reserve, to temporarily fill an open Fed seat
The AI-Powered Education Revolution: Market Potential and Transformative Impact
Chikungunya Virus Outbreak in Southern China: Over 7,000 Hospitalized
French wine makers have seen catastrophic damage to vines that were almost ready to be harvested after the worst fires in more than 70 years burned through the south of the country
US Lawmaker Probes Intel CEO’s China Ties Amid National Security Concerns
Brazilian President Lula says he’ll contact the leaders of BRICS states to propose a unified response to U.S. tariffs
Trump Open to Meeting Putin as Soon as Next Week, with Possible Trilateral Summit Including Zelenskiy
Katy Perry and Justin Trudeau spark dating rumors, joining high stakes world of celeb-politician romances
US envoy Steve Witkoff arrived in Moscow to seek a breakthrough in the Ukraine war ahead of President Trump’s peace deadline
WhatsApp Deletes 6.8 Million Scam Accounts Amid Rising Global Fraud
Nine people have been hospitalized and dozens of salmonella cases have been reported after an outbreak of infections linked to certain brands of pistachios and pistachio-containing products, according to the Public Health Agency of Canada
Karol Nawrocki Inaugurated as Poland’s President, Setting Stage for Clash with Tusk Government
Trump Signals JD Vance as ‘Most Likely’ MAGA Successor for 2028
US Charges Two Chinese Nationals for Illegal Nvidia AI Chip Exports
Texas Residents Face Water Restrictions While AI Data Centers Consume Millions of Gallons
U.S. Tariff Policy Triggers Market Volatility Amid Growing Global Trade Tensions
Tariffs, AI, and the Shifting U.S. Macro Landscape: Navigating a New Economic Regime
Representative Greene Urges H-1B Visa Cuts Amid U.S.-India Trade Tensions
U.S. House Committee Subpoenas Clintons and Senior Officials in Epstein Investigation
Sydney Sweeney Registered as Republican as Controversial American Eagle Ad Sparks Debate
Trump Accuses Major Banks of Politically Motivated Account Denials and Prepares Executive Order
TikTok Removes Huda Kattan Video Over Anti-Israel Conspiracy Claims
Trump Threatens Tariffs on India Over Russian Oil Imports
German Finance Minister Criticizes Trump’s Attacks on Institutions
U.S. Proposes Visa Bond of Up to $15,000 for Some Applicants
U.S. Farmers Increase Lobbying Amid Immigration Crackdown
Elon Musk Receives $23.7 Billion Tesla Stock Award
Texas House Paralyzed After Democrats Walk Out Over Redistricting
Mexican Cartels Complicate Sheinbaum’s U.S. Security Talks
×