• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Techspyware

Latest Apple patch blocks spyware that infects iPhones and Macs

By
Kartikay Mehrotra
Kartikay Mehrotra
,
William Turton
William Turton
,
Davide Scigliuzzo
Davide Scigliuzzo
and
Bloomberg
Bloomberg
Down Arrow Button Icon
By
Kartikay Mehrotra
Kartikay Mehrotra
,
William Turton
William Turton
,
Davide Scigliuzzo
Davide Scigliuzzo
and
Bloomberg
Bloomberg
Down Arrow Button Icon
September 13, 2021, 7:34 PM ET

Apple said it patched a security flaw in the Messages app after security researchers determined that Israel-based NSO Group used it to “exploit and infect” the latest devices with spyware.

The flaw, disclosed Monday by Citizen Lab, allowed a hacker using NSO’s Pegasus malware to gain access to a device owned by an unnamed Saudi activist, according to security researchers. Apple said the flaw could be exploited if a user on a vulnerable device received a “maliciously crafted” PDF file. 

The flaw was a “zero-day” vulnerability, a term that refers to recently discovered bugs that hackers can exploit and haven’t yet been patched. Victims didn’t have to click on the malicious file for it to infect their devices, something known as a “zero-click” exploit, according to a report released by Citizen Lab, a cyber-research unit of the University of Toronto.

“What this highlights is that chat apps are the soft underbelly of device security,” said John Scott-Railton, senior researcher at Citizen Lab, in a text message. “They are ubiquitous, which makes them really attractive, so they are an increasingly common target for attackers.

“They need to be a major priority for security,” he added. “Narrowing the attack surface from chat apps will go a long way toward making all of our devices more secure.”

Apple is patching the bug on the iPhone, iPad, Mac, and Apple Watch via iOS 14.8, iPadOS 14.8, macOS 11.6 and watchOS 7.6.2 software updates. The software releases came the day before Apple’s Sept. 14 product launch event, which will likely spur the release of iOS 15, Apple’s next major software update that will contain additional security protections. 

“Apple is aware of a report that this issue may have been actively exploited,” the iPhone maker said on its website. 

Apple shares were little changed in extended trading after closing at $149.55 in New York.

NSO Group, in a statement, said the company “will continue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime.”

The NSO Group has been the subject of repeated criticism by Citizen Lab and other organizations after its spyware has been discovered on the phones of activists and journalists critical of repressive regimes. In its report Monday, Citizen Lab accused NSO Group of facilitating “despotism-as-a-service for unaccountable government security agencies” and argued that regulation is “desperately needed.”

NSO Group has insisted that the spyware is intended to be used to fight terrorism and crime, not to aid in human rights abuses.

In June, the company published its first “Transparency and Responsibility Report,” which defended its technology and efforts to curb misuse by customers. 

The White House has raised concerns about NSO Group with senior Israeli officials, the Washington Post reported. 

In December, Citizen Lab reported that NSO spyware was used to target the devices of 36 Al Jazeera employees. Citizen Lab said that it believed the hacks were carried out on behalf of Saudi Arabia and the United Arab Emirates. The hack in 2020 is similar to the one disclosed Monday because it didn’t require the victim to click on a malicious link, meaning there is no way to defend from the hack. NSO Group denied the report.  

Subscribe to Coins2Day Daily to get essential business stories straight to your inbox each morning.
About the Authors
By Kartikay Mehrotra
See full bioRight Arrow Button Icon
By William Turton
See full bioRight Arrow Button Icon
By Davide Scigliuzzo
See full bioRight Arrow Button Icon
By Bloomberg
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.