techwithmuchiri
  • Home
  • Reviews
  • Smartphones
    • Android
    • Apple
  • How-To
  • Tech Explained
  • Startups
  • Cybersecurity
  • Buying Guides
  • More
    • Legal Tech
    • Opinions
    • Entertainment
No Result
View All Result
  • Home
  • Reviews
  • Smartphones
    • Android
    • Apple
  • How-To
  • Tech Explained
  • Startups
  • Cybersecurity
  • Buying Guides
  • More
    • Legal Tech
    • Opinions
    • Entertainment
No Result
View All Result
techwithmuchiri
Home Cybersecurity

Apple urges immediate update to fix Pegasus Spyware attacking iPhones

The zero-days were found in the Image I/O and Wallet frameworks of iOS.

Muchiri by Muchiri
September 8, 2023
in Cybersecurity
0
Apple urges immediate update to fix Pegasus Spyware attacking iPhones
Share on FacebookShare on Twitter

Jump ahead

  • Key Highlights
  • Pegasus Spyware Deployed via Malicious Image Files
  • Update Devices Urgently, Enable Lockdown Mode
  • Growth of iPhone Zero-Days Underscores Vigilance Need

Key Highlights

  1. Apple has released urgent updates to fix 2 zero-days being exploited to deploy Pegasus spyware on fully updated iPhones.
  2. The iOS zero-days allowed zero-click remote code execution via malicious image files sent over iMessage.
  3. Apple has already patched 13 in-the-wild zero-days across its products in 2023, underscoring the need for swift security updates.

Apple has released emergency iOS updates to fix two actively exploited zero-day vulnerabilities that were being used to deploy the Pegasus spyware on fully updated iPhones.

The zero-days, tracked as CVE-2023-41064 and CVE-2023-41061, were uncovered by researchers at Citizen Lab. They allowed zero-click remote code execution on iPhones running the latest iOS 16.6.

Pegasus Spyware Deployed via Malicious Image Files

Dubbed BLASTPASS by Citizen Lab, the exploit chain involved sending maliciously crafted PassKit image attachments over iMessage. Once triggered, the Pegasus spyware would be installed without any action from the user.

Also Read: Google is switching all Chrome users to Enhanced Safe Browsing for real time Phishing protection

“We refer to the exploit chain as BLASTPASS. The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” Citizen Lab said.

“The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim.”

Pegasus Spyware attacking iPhones

The zero-days were found in the Image I/O and Wallet frameworks of iOS. CVE-2023-41064 stems from a buffer overflow in image processing, while CVE-2023-41061 is a validation issue exploit.

Both flaws grant arbitrary remote code execution, enabling spyware installation on unpatched devices. They impact iPhone 8 and newer models, various iPad models and Apple Watch Series 4 onwards running iOS 16.6 and below.

Update Devices Urgently, Enable Lockdown Mode

Apple has addressed the vulnerabilities in iOS 16.6.1, iPadOS 16.6.1 and other platform updates by improving memory handling and input validation.

Citizen Lab strongly urged Apple users to install the latest updates immediately to protect against attacks leveraging these iPhone zero-days. Users especially at high risk of targeting should also consider enabling Lockdown Mode for added security.

Growth of iPhone Zero-Days Underscores Vigilance Need

So far in 2023, Apple has already patched 13 in-the-wild zero-days across its product portfolio. This includes nine iOS zero-days alone since February.

The proliferation of iPhone and iPad zero-days highlights the resources and determination of private attack groups. It emphasizes the critical importance of swiftly applying security updates before threat actors can exploit them.

For Apple customers, maintaining software currency through prompt patching is essential to thwarting the growing spread of commercial spyware like Pegasus.

Join us on Telegram
Tags: ApplePegasus Spyware
Previous Post

Google is switching all Chrome users to Enhanced Safe Browsing for real time Phishing protection

Next Post

Samsung opens new Maralal Oasis outlet in Nairobi to enhance customer experience

Muchiri

Muchiri

Tech editor at Tech with Muchiri. I specialize in covering various aspects of technology and reviewing the latest gadgets. If you have any inquiries or wish to contact me, feel free to reach out to me via email: techwithmuchiri@gmail.com

Next Post
Samsung opens new Maralal Oasis outlet in Nairobi to enhance customer experience

Samsung opens new Maralal Oasis outlet in Nairobi to enhance customer experience

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

TechSpot Africa – The Podcast

TechSpot Africa
TechSpot Africa

Listen to the latest insights in the tech space on the TechSpot Africa Podcast, hosted by Nigel Jr. from tech-space.africa and Antony Muchiri of techwithmuchiri.com. Stay ahead in the tech game, tune in now! Subscribe and share!

Listen OnSpotify
Proposed TikTok Ban in Kenya, Starlink in Kenya, World Coin Craze, Samsung’s New Foldables and Nigel’s Interview with Watu Credit
byTechspot Africa

In this episode of the podcast, we discuss the proposed TikTok ban in Kenya, the arrival of Starlink in Kenya, the world coin craze, Samsung's new foldables, and Nigel's interview with Watu Credit.

  • Proposed TikTok Ban in Kenya: The Kenyan government is considering banning TikTok, citing concerns about the app's impact on children and young people. We discuss the pros and cons of this proposal and what it could mean for Kenyans who use TikTok.
  • Starlink in Kenya: Starlink, the satellite internet service from SpaceX, is now available in Kenya. We discuss what this means for Kenyans who have been struggling with unreliable and expensive internet access.
  • World Coin Craze: A new cryptocurrency called World Coin is causing a stir in Kenya. We discuss what World Coin is and why it is so popular among Kenyans.
  • Samsung's New Foldables: Samsung has just released its new foldable smartphones, the Galaxy Z Fold 5 and the Galaxy Z Flip 5. We take a look at these new devices and discuss whether they are worth the high price tag.
  • Nigel's Interview with Watu Credit: Nigel recently interviewed the Country Manager of Watu Credit, a leading asset financing company in Kenya.

We hope you enjoy this episode of the podcast!

Proposed TikTok Ban in Kenya, Starlink in Kenya, World Coin Craze, Samsung’s New Foldables and Nigel’s Interview with Watu Credit
Proposed TikTok Ban in Kenya, Starlink in Kenya, World Coin Craze, Samsung’s New Foldables and Nigel’s Interview with Watu Credit
August 16, 2023
Techspot Africa
Is threads a Threat to Twitter, Nothing Phone (2) First Impressions and is Google’s First attempt at a Foldable a flop?
July 13, 2023
Techspot Africa
Digital Content Creator Tax is a bad idea, Apple Vision Pro is the Future, and Transsion Vs Samsung Vs Others
June 14, 2023
Techspot Africa
Exploring why Samsung S23 Series sales skyrocketing, the upper-budget smartphone influx, and triple folding Samsung tablet rumors.
April 11, 2023
Techspot Africa
EP3: Buying a Refurbished Flagship vs A New Midrange Smartphone and The Tecno Phantom V Fold Shocked us!
March 30, 2023
Techspot Africa
Kenyan Labour is Cheap, Twitter’s 2FA Charge, Facebook’s Paid Verification, OPPO Reno8 T Pricing, and More!
February 21, 2023
Techspot Africa
Google Bard is the ChatGPT Killer? Samsung S23 Pricing in Kenya is Weird and OPPO Reno8t First Impressions
February 7, 2023
Techspot Africa
Search Results placeholder
  • About Us
  • Contact Us
  • Privacy Policy
Email us: techwithmuchiri@gmail.com

© 2023 Tech With Muchiri

No Result
View All Result
  • Home
  • Reviews
  • Smartphones
    • Android
    • Apple
  • How-To
  • Tech Explained
  • Startups
  • Cybersecurity
  • Buying Guides
  • More
    • Legal Tech
    • Opinions
    • Entertainment

© 2023 Tech With Muchiri

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT