Security

Malicious websites were used to secretly hack into iPhones for years, says Google

Comment

google iphones
Image Credits: Getty Images

Security researchers at Google say they’ve found a number of malicious websites which, when visited, could quietly hack into a victim’s iPhone by exploiting a set of previously undisclosed software flaws.

Google’s Project Zero said in a deep-dive blog post published late on Thursday that the websites were visited thousands of times per week by unsuspecting victims, in what they described as an “indiscriminate” attack.

“Simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant,” said Ian Beer, a security researcher at Project Zero.

He said the websites had been hacking iPhones over a “period of at least two years.”

The researchers found five distinct exploit chains involving 12 separate security flaws, including seven involving Safari, the in-built web browser on iPhones. The five separate attack chains allowed an attacker to gain “root” access to the device — the highest level of access and privilege on an iPhone. In doing so, an attacker could gain access to the device’s full range of features normally off-limits to the user. That means an attacker could quietly install malicious apps to spy on an iPhone owner without their knowledge or consent.

Google said based off their analysis, the vulnerabilities were used to steal a user’s photos and messages as well as track their location in near-real time. The “implant” could also access the user’s on-device bank of saved passwords.

The vulnerabilities affect iOS 10 through to the current iOS 12 software version.

Google privately disclosed the vulnerabilities in February, giving Apple only a week to fix the flaws and roll out updates to its users. That’s a fraction of the 90 days typically given to software developers, giving an indication of the severity of the vulnerabilities.

Apple issued a fix six days later with iOS 12.1.4 for iPhone 5s and iPad Air and later.

Beer said it’s possible other hacking campaigns are currently in action.

The iPhone and iPad maker in general has a good rap on security and privacy matters. Recently the company increased its maximum bug bounty payout to $1 million for security researchers who find flaws that can silently target an iPhone and gain root-level privileges without any user interaction. Under Apple’s new bounty rules — set to go into effect later this year — Google would’ve been eligible for several million dollars in bounties.

When reached, a spokesperson for Apple declined to comment.

Apple expands its bug bounty, increases maximum payout to $1M

More TechCrunch

The company is in various stages of developing and piloting a range of initiatives focused on dealing with bad actors, harassment, spam, fake accounts, video safety, and more.

Bluesky addresses trust and safety concerns around abuse, spam, and more

Fal.ai, a dev-focused platform for AI-generated audio, video, and images, today revealed that it’s raised $23 million in funding from investors including Andreessen Horowitz (a16z), Black Forest Labs co-founder Robin…

Fal.ai, which hosts media-generating AI models, raises $23M from a16z and others

A House committee overwhelmingly voted to approve a bill that would require new cars to be built with AM radio at no additional cost to the owner. The AM for…

Bill requiring AM radio in new cars gets closer to law

The Vive Focus Vision has enough firepower under the hood to appeal to PC gamers tethered via the DisplayPort.

HTC takes on Apple’s Vision Pro and PC Gaming with $1,000 Vive Focus Vision

The reversal comes as EV startup Fisker prepares to enter the fourth month of its Chapter 11 bankruptcy process.

Fisker reverses course on making Ocean owners pay for recall repairs

iOS 18 offers the most control over the look and feel of your iPhone’s user interface than any other version of Apple’s mobile operating system to date.

Three new ways to personalize your iPhone’s Home Screen in iOS 18

LinkedIn may have trained AI models on user data without updating its terms. LinkedIn users in the U.S. — but not the EU, EEA, or Switzerland, likely due to those…

LinkedIn scraped user data for training before updating its terms of service

Hiya, folks, welcome to TechCrunch’s regular AI newsletter. If you want this in your inbox every Wednesday, sign up here. It’s been just a few days since OpenAI revealed its latest…

This Week in AI: Why OpenAI’s o1 changes the AI regulation game

The FBI, NSA and other U.S. government agencies detailed a Chinese-government operation that used 260,000 of internet-connected devices to launch cyberattacks.

US government ‘took control’ of a botnet run by Chinese government hackers, says FBI director

The pitch sounds a bit sci-fi: a helmet called Lily that people undergoing chemotherapy wear to prevent hair loss, which is a common side effect of the treatment.

Luminate’s hair-saving chemo helmet nears release, as new funding goes toward home cancer care

At its Made On YouTube event on Wednesday, the company announced a new dedicated space for creators to interact with their fans and viewers. The space, called “Communities,” is kind…

YouTube launches Communities, a Discord-like space for creators and fans to interact with each other

Amazon’s Buy with Prime program, which lets shoppers with a Prime membership purchase items from third-party stores and check out using their Amazon account, is getting a new payment option:…

Amazon adds PayPal as a payment option to Buy with Prime

Edera, a startup looking to simplify and improve how Kubernetes containers and AI workloads are secured by offering a new hypervisor, today announced that it has raised a $5 million…

Edera is building a better Kubernetes and AI security solution from the ground up

YouTube creators no longer have to rely solely on the recommendation algorithm, search results, or collabs to help them grow their audience. At the company’s Made On YouTube event on…

YouTube unveils ‘Hype,’ a new way for fans to help smaller creators grow their reach

Extend the buzz of TechCrunch Disrupt 2024 beyond the main event by hosting an exclusive Side Event. Expose your brand to 10,000 Disrupt attendees and the surrounding Bay Area tech…

Last Week: Amplify your brand by hosting a Side Event at TechCrunch Disrupt 2024

The main attraction of YouTube’s Made On YouTube event on Wednesday morning was, you guessed it, artificial intelligence. The company announced that it is integrating Google DeepMind’s AI video generation…

YouTube Shorts to integrate Veo, Google’s AI video model 

At its Made On YouTube event on Wednesday, the company announced that creators can now brainstorm ideas for videos with the help of AI right within YouTube Studio. YouTube will…

YouTube Studio now lets creators brainstorm video ideas with the help of AI

The real estate market and many real estate-focused startups were hit hard when mortgage rates skyrocketed in 2022, but that didn’t stop industry veteran Clelia Warburg Peters from leaving her…

Era Ventures raises $88M first fund for transforming the ‘built’ environment

Runway, a startup developing AI video tools, including video-generating models, has partnered with Lionsgate — the studio behind the “John Wick” and “Twilight” franchises — to train a custom video…

Generative AI startup Runway inks deal with a major Hollywood studio

Gamebeast is a live operations tooling platform that lets developers modify games without needing to release a new version or interrupt an ongoing game.

The 22-year-old building Roblox developer tools to make gaming more efficient

Apple announced Wednesday that its generative AI offering will be available in even more languages in 2025. Additions to Apple Intelligence include English (India), English (Singapore), German, Italian, Korean, Portuguese,…

Apple Intelligence will support German, Italian, Korean, Portuguese, and Vietnamese in 2025

Featured Article

iPhone 16 Pro Max review: A $1,200 glimpse at a more intelligent future

The iPhone 16’s headliner features are Apple Intelligence, which will be rolled out next month, and its camera system.

iPhone 16 Pro Max review: A $1,200 glimpse at a more intelligent future

The most interesting of the bunch is a new adhesive design that can be loosened by applying low voltage from a 9-volt battery.

Here’s how Apple is making iPhone 16 more repairable

Parents understand the challenge of keeping young kids engaged in online learning. Nurture is a new app designed for children aged 4 to 7 that features interactive content and games…

Nurture teaches kids important life skills through interactive gameplay and entertainment

Google has succeeded in overturning a $1.7 billion antitrust penalty handed down by the European Union back in March 2019.

Google nets court win against EU’s $1.7B AdSense antitrust decision

23andMe, the personal genomics company, went public in early 2021 via a merger with a blank check company that valued it at $3.5 billion. Then its fortunes began to sink.…

23andMe sees independent board directors quit en masse

California governor Gavin Newsom said there are 38 bills on his desk that would create laws around artificial intelligence on Tuesday, but one looms larger than all of them: SB…

Governor Newsom on California AI bill SB 1047: ‘I can’t solve for everything’

Amazon has named long-time executive Samir Kumar as the new head of its India consumer business, a month after its domestic business’ head resigned.

Amazon taps long-time exec to lead India business as competition intensifies

Al Gore has enjoyed a very successful career, including as a U.S. senator, U.S. Vice President, U.S. presidential nominee, and even Nobel Peace Prize winner in 2007 for “informing the…

Al Gore roasts corporations and politicians, comparing their climate crisis promises to ‘New Year’s resolutions’

On Tuesday, California governor Gavin Newsom signed some of America’s toughest laws yet regulating the artificial intelligence sector. Three of these laws crack down on AI deepfakes that could influence…

California’s 5 new AI laws crack down on election deepfakes and actor clones