San Antonio Express-News

Apple puts out emergency security updates

-

Apple on Monday issued emergency software updates for a critical vulnerabil­ity in its products after security researcher­s uncovered a flaw that allows highly invasive spyware from Israel’s NSO Group to infect anyone’s iphone, iwatch or Mac computer without so much as a click.

Apple’s security team has been working around the clock to develop a fix since Tuesday, after researcher­s at Citizen Lab, a cybersecur­ity watchdog organizati­on at the University of Toronto, discovered that a Saudi activist’s iphone had been infected with spyware from NSO Group.

The spyware, called Pegasus, used a novel method to invisibly infect an Apple device without the victim’s knowledge for as long as six months. Known as a “zero click remote exploit,” it is considered the Holy Grail of surveillan­ce because it allows government­s, mercenarie­s and criminals to secretly break into a victim’s device without tipping them off.

Using the zero-click infection method, Pegasus can turn on a user’s camera and microphone, record their messages, texts, emails, calls — even those sent via encrypted messaging and phone apps like Signal — and send it back to NSO’S clients at government­s around the world.

“This spyware can do everything an iphone user can do on their device and more,” said John Scott-railton, a senior researcher at Citizen Lab, who teamed with Bill Marczak, a senior research fellow at Citizen Lab, on the finding.

In the past, victims only learned their devices were infected by spyware after receiving a suspicious link texted to their phone or email. But NSO Group’s zero-click capability gives the victim no such prompt and enables full access to a person’s digital life. These capabiliti­es can fetch millions of dollars on the undergroun­d market for hacking tools.

An Apple spokesman confirmed Citizen Lab’s assessment and said the company planned to add spyware barriers to its next IOS 15 software update, expected later this year.

NSO Group did not immediatel­y respond to inquiries Monday.

NSO Group has long drawn controvers­y. The company has said it sells its spyware to only government­s that meet strict human rights standards. But over the past six years, its Pegasus spyware has turned up on the phones of activists, dissidents, lawyers, doctors, nutritioni­sts and even children in countries like Saudi Arabia, the United Arab Emirates and Mexico.

Scott-railton urged Apple customers to run their software updates.

“Do you own an Apple product? Update it today,” he said.

Newspapers in English

Newspapers from United States