Apple advises immediate update to iOS 9.3.5 after discovery of targeted iPhone spyware

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Independent researchers tracked down malware sent to a Middle Eastern human-rights activist and alerted Apple, which patched three separate zero-day exploits.

Apple released an update to iOS 9 on Thursday—iOS 9.3.5—that patches multiple critical zero-day vulnerabilities that have been shown to already have been deployed, allegedly by governments to target activists and dissidents, according to a report from Citizen Lab and Lookout Security. Apple turned around an update within 10 days from when the company received Citizen Lab’s initial report. The update is recommended immediately for all iOS 9 devices.

When used together, the exploits allow someone to hijack an iOS device and control or monitor it remotely. Hijackers would have access to the device’s camera and microphone, and could capture audio calls even in otherwise end-to-end secured apps like WhatsApp. They could also grab stored images, tracking movements, and retrieve files.

Some of the exploits may have been discovered months ago or longer, so there’s no way to know how widely they’re in use, but details suggest these active exploits in previous versions of iOS 9 weren’t in wide use and were deployed against individual targets.

“What we have seen from looking at these exploits is that it seems that they have been in the wild a bit longer than the 9.3.3/9.3.4 timeframe,” report co-author Bill Marczak of Citizen Lab said in an interview. iOS 9.3.3 was released on July 18.

An Apple spokesperson said, “We were made aware of this vulnerability and immediately fixed it with iOS 9.3.5. We advise all of our customers to always download the latest version of iOS to protect themselves against potential security exploits.”

Jailbreaks have been demonstrated but not yet released for iOS 9.3.4, and it’s possible those jailbreaks relied on one or more aspects of the three flaws now patched.



Read more: Apple advises immediate update to iOS 9.3.5 after discovery of targeted iPhone spyware
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
I updated the IPhone honestly is jail breaking really worth it? A computer can emulate almost anything even while being up to date. Not updating a device is a security risk.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I updated the IPhone honestly is jail breaking really worth it? A computer can emulate almost anything even while being up to date. Not updating a device is a security risk.
sometimes, jailbreaking iphone is worth it. In my country, people are using a lot of locked iphones (japan, korea, US carriers), they have to use a small chip to make the iphones to be able to get the signal. However there are still some software limitations that can only be fixed after jailbreaking. People in my country (except businessmen or ppl who care) vỉtually don't know much/don't care about privacy like western countries so for us, it's fine, convenience >> privacy
jailbroken devices can also add a hosts file to block apple tracking services and secrete outboard connections, I saw that in a shared hosts file with an explanation what it blocked years ago

and of course, cracked apps since it was extremely hard to buy an app 2-3 years ago because most people here never use credit cards

I heard somewhere that apple actually worked with other companies and created those kind of security problems to force people to update to ios 9.3.4 and 9.3.5. rumour
If we dont update ios, idevices will automatically download the latest ios version and it will take around 1-2Gb of storage. It will redownload each time we delete it. I dont wanna upgrade my iphone 5 to ios10 :( so I had to use a profile to block my non-jailbroken ip5 from checking for update

Sorry, I just want to tell what I heard, not to tell ppl to jailbreak and expose his/her devices to security problems :)
 
Last edited:

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
sometimes, jailbreaking iphone is worth it. In my country, people are using a lot of locked iphones (japan, korea, US carriers), they have to use a small chip to make the iphones to be able to get the signal. However there are still some software limitations that can only be fixed after jailbreaking. People in my country (except businessmen or ppl who care) vỉtually don't know much/don't care about privacy like western countries so for us, it's fine, convenience >> privacy
jailbroken devices can also add a hosts file to block apple tracking services and secrete outboard connections, I saw that in a shared hosts file with an explanation what it blocked years ago

and of course, cracked apps since it was extremely hard to buy an app 2-3 years ago because most people here never use credit cards

I heard somewhere that apple actually worked with other companies and created those kind of security problems to force people to update to ios 9.3.4 and 9.3.5. rumour
If we dont update ios, idevices will automatically download the latest ios version and it will take around 1-2Gb of storage. It will redownload each time we delete it. I dont wanna upgrade my iphone 5 to ios10 :( so I had to use a profile to block my non-jailbroken ip5 from checking for update

Sorry, I just want to tell what I heard, not to tell ppl to jailbreak and expose his/her devices to security problems :)

Yes I understand where you are getting at but like android apps "cracked" ones can have a potential risk. Like andriod apps outside of the app store can be filled with malware and pretend to be the real thing. Apple isn't really collecting any data from what I understand other than location services which can be disabled. A lot of app permissions can be disabled. As for the updating issue. I don't really believe it works like that. If you have an older iphone it can only go to a certain ios and necessarily isn't the latest. I have an iPhone that can't update past 6... Hopefully this explained a little. :)
 
  • Like
Reactions: Evjl's Rain

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top