Beautiful Virgin Islands

Friday, Apr 03, 2026

IOS is secure? Never was. Hackers breached iPhone users data for years

Cybercriminals implanted iPhones with spyware by exploiting a hole in Apple's operating system

Hackers planted spyware on iPhone users' devices over a two-year period by exploiting a vulnerability in the technology's operating systems, Google said Friday.

The bad actors targeted a group of infected websites that, when visited by iPhone users, attacked the devices and in some cases installed malware, according to Ian Beer of Project Zero, a team of Google security analysts that investigates cybercrime.

"There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant. We estimate that these sites receive thousands of visitors per week," Beer wrote in a blog post.

Using the implant, hackers could access Apple customers' data, including their passwords and personal contacts, as well as messages sent through iMessage, WhatsApp, Gmail and Google Hangouts, according to Project Zero researchers.

Almost every version of Apple's iPhone operating system — from iOS 10 through to the latest version of iOS 12 — was vulnerable, he said. Still, it's unclear how many users might have been affected.


Old bug, new hack

The security bugs Beer identified aren't new, but rather were exploited in novel ways.

"Ian shows this is the first time these types of vulnerabilities have been used out on the wide internet, where if the malicious code was present on a certain website that was accessed, the unsuspecting user would be infected, and remain blissfully ignorant of it," said operating system internals researcher Jonathan Levin.

In this case, no user intervention, such as a prompt to click on a link, was required for an iPhone to get inflected.

The scope of the hack suggests it was backed by a nation rather than an individual, Levin said. "It requires a lot of research, and there has to be an endgame motive for this," he told CBS MoneyWatch. "It's possible that those behind the hack targeted a specific demographic or interest groups."

"My personal hunch, because of the level of proficiency and efficacy of the exploits, is that this is not the work of your average hacker," he added.

Neither is there a sure-fire way for users to protect themselves against security breaches, Beer said. "All that users can do is be conscious of the fact that mass exploitation still exists and behave accordingly; treating their mobile devices as both integral to their modern lives, yet also as devices which when compromised, can upload their every action into a database to potentially be used against them."

Google said it reported its findings to Apple in February, after which the tech giant released an updated operating system to fix the flaws.


Android's no safer

While Beer highlights some of the iPhone's vulnerabilities, the attack shouldn't be misread to suggest that Google's Android operating system is safer, Levin said.

"The takeaway shouldn't be, 'I'm going to use Android from now on because it's more secure.' That's far from it," he said. "Similar and/or possibly worse bugs exist in Android and other operating systems as well. Google Project Zero simply chose to highlight iOS this time."

Apple claims to be the most secure operating system, and for good reason. "Apple genuinely invests extreme efforts in securing iOS on multiple layers, down to their proprietary hardware, and in some aspects are still way ahead of Android," Levin said.

Newsletter

Related Articles

Beautiful Virgin Islands
0:00
0:00
Close
Trump’s Strategic Pressure on UK Seen as Push for Stronger Alignment and Fairer Terms
UK Focuses on Trade Finance to Secure Critical Materials for Defence and Energy Sectors
Majority of UK Businesses Hit by Middle East Conflict While Confidence Holds Firm
UK Royal Navy Faces Renewed Scrutiny as Debate Intensifies Over Capability and Readiness
Reform UK Faces Mounting Distractions as Policy Agenda Struggles to Gain Traction
Investigation Launched Into Northern Cyprus IVF Clinics After UK Families Receive Incorrect Sperm
International Meeting Issues Unified Call to Safeguard Navigation Through Strait of Hormuz
Potential Strait of Hormuz Closure Raises Concerns Over UK Food and Medicine Supply Chains
UK Leads Coalition of Over Forty Nations Urging Iran to Reopen Strait of Hormuz
UK Secures Tariff-Free Access for Medicines in Landmark US Pharma Trade Agreement
King Charles III Invited to Address Joint Session of U.S. Congress in Rare Diplomatic Honor
Debate Grows Over Whether Expanded North Sea Drilling Can Reduce UK Energy Bills
UK Faces Heightened Risk of Jet Fuel Shortages, Airline Chief Warns
UK Ends Police Investigations into Lawful Social Media Posts After Review Finds Overreach
Abramovich Moves to Establish Charity for Frozen Chelsea Sale Proceeds Amid UK Dispute
Starmer Reaffirms NATO Commitment While Responding to Trump’s Strategic Critique
UK Aid Reductions Raise Fears of Severe Human Impact Across Parts of Africa
UK Signals Renewed Push for EU Cooperation as Iran Conflict Reshapes Security Landscape
Bank of England Signals Caution as Bailey Advises Markets Against Expecting Rate Hikes
UK to Convene Global Coalition to Restore Shipping Through Strait of Hormuz
Trump Signals Possible NATO Reassessment, Emphasizes Stronger U.S. Strategic Autonomy
Australia Joins British-Led Efforts to Reopen Strait of Hormuz Amid Escalating Tensions
King Charles Plans US State Visit as UK Strengthens Ties with Trump Leadership
UK Regulator Launches Investigation Into Microsoft’s Business Software Practices
Kanye West Set for High-Profile Return to UK Stage at Wireless Festival
Trump Presses Europe to Strengthen Commitment as Iran Conflict Escalates
UK to Deploy Additional Troops to Middle East Amid Rising Regional Tensions
UK Authorities Face Claims of Heavy-Handed Measures in Monitoring Released Pro-Palestine Activists
Trump Calls on UK to Secure Its Own Energy as Iran Conflict Intensifies
Nigel Farage Declines Invitation to UK Conservative Conference Led by Liz Truss
Trump Warns Allies to Take Responsibility as Rift Deepens with UK and France Over Iran Conflict
How Britain’s Prime Minister Controls U.S. Bomber Access in Escalating Iran Conflict
Trump Urges Allies to Secure Their Own Oil Supplies as Hormuz Crisis Disrupts Global Energy
Russia Expels British Diplomat as UK Pushes Back Against Pressure
White House App Faces Scrutiny After Claims of Continuous User Location Tracking
BBC Faces Scrutiny Over Allegations of Paid Content Linked to Saudi Arabia
UK-France Coastal Patrol Agreement Nears Breakdown Amid Migration Pressures
UK Police Detain Pro-Palestine Activist Again Weeks After Bail Release
FTSE 100 Advances as Energy and Mining Shares Gain Amid Middle East Tensions
Eli Lilly Seeks UK Pricing Deal to Unlock Renewed Pharmaceutical Investment
Three Arrested in UK After Massive Cocaine Haul Discovered Hidden in Banana Shipment
UK Fuel Prices Poised for Further Surge Amid Global Energy Pressures
Apple Subsidiary Penalized by UK Authorities for Breach of Moscow Sanctions
Western Allies Intensify Coordinated Sanctions Strategy Against Russia
UK Lawmakers Face Criticism Over Renewed Push for Social Media Restrictions
Starmer Signals UK Crackdown on Addictive Social Media Features
Rising Costs Push One in Five UK Hospitality Businesses to the Brink of Closure
Man Arrested on Suspicion of Attempted Murder After Car Strikes Pedestrians in UK, Injuring Seven
Escalating Conflict Involving Iran Tightens Fiscal Pressures and Highlights UK Economic Vulnerabilities
UK Moves to Confront Russian ‘Shadow Fleet’ Operating in Its Waters
×