Cyber arms dealer exploits new iPhone software vulnerability, affecting most versions, say researchers | The Business Standard
Skip to main content
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Get the Paper
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
The Business Standard

Friday
July 18, 2025

Sign In
Subscribe
  • Latest
  • Economy
    • Banking
    • Stocks
    • Industry
    • Analysis
    • Bazaar
    • RMG
    • Corporates
    • Aviation
  • Videos
    • TBS Today
    • TBS Stories
    • TBS World
    • News of the day
    • TBS Programs
    • Podcast
    • Editor's Pick
  • World+Biz
  • Features
    • Panorama
    • The Big Picture
    • Pursuit
    • Habitat
    • Thoughts
    • Splash
    • Mode
    • Tech
    • Explorer
    • Brands
    • In Focus
    • Book Review
    • Earth
    • Food
    • Luxury
    • Wheels
  • Subscribe
    • Get the Paper
    • Epaper
    • GOVT. Ad
  • More
    • Sports
    • TBS Graduates
    • Bangladesh
    • Supplement
    • Infograph
    • Archive
    • Gallery
    • Long Read
    • Interviews
    • Offbeat
    • Magazine
    • Climate Change
    • Health
    • Cartoons
  • বাংলা
FRIDAY, JULY 18, 2025
Cyber arms dealer exploits new iPhone software vulnerability, affecting most versions, say researchers

Tech

Reuters
14 September, 2021, 10:30 am
Last modified: 14 September, 2021, 10:38 am

Related News

  • Software slowdown disrupts customs operations nationwide
  • FaceTime in iOS 26 will pause video calls if sensitive content detected
  • Proton ecosystem review: A privacy-first alternative to big tech
  • Foxconn sends 97% of India iPhone exports to US as Apple tackles Trump's tariffs
  • From Dhaka to Paris: How Kaz Software is making its place on global stage

Cyber arms dealer exploits new iPhone software vulnerability, affecting most versions, say researchers

Apple said it fixed the vulnerability in Monday's software update, confirming Citizen Lab's finding

Reuters
14 September, 2021, 10:30 am
Last modified: 14 September, 2021, 10:38 am
Photo :Reuters
Photo :Reuters

A cyber surveillance company based in Israel developed a tool to break into Apple iPhones with a never-before-seen technique that has been in use since at least February, internet security watchdog group Citizen Lab said on Monday.

The discovery is important because of the critical nature of the vulnerability, which requires no user interaction and affects all versions of Apple's iOS, OSX, and watchOS, except for those updated on Monday.

The tool developed by the Israeli firm, named NSO Group, defeats security systems designed by Apple in recent years.

The Business Standard Google News Keep updated, follow The Business Standard's Google news channel

Apple said it fixed the vulnerability in Monday's software update, confirming Citizen Lab's finding. 

"After identifying the vulnerability used by this exploit for iMessage, Apple rapidly developed and deployed a fix in iOS 14.8 to protect our users," said Ivan Krstić, head of Apple Security Engineering and Architecture, in a statement. "Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals."

"While that means they are not a threat to the overwhelming majority of our users, we continue to work tirelessly to defend all our customers, and we are constantly adding new protections for their devices and data," he added.

An Apple spokesperson declined to comment on whether the hacking technique came from NSO Group.

In a statement to Reuters, NSO did not confirm or deny that it was behind the technique, saying only that it would "continue to provide intelligence and law enforcement agencies around the world with life-saving technologies to fight terror and crime."

'SOFT UNDERBELLY OF DEVICE SECURITY'

Citizen Lab said it found the malware on the phone of an unnamed Saudi activist and that the phone had been infected with spyware in February. It is unknown how many other users may have been infected.

The intended targets would not have to click on anything for the attack to work. Researchers said they did not believe there would be any visible indication that a hack had occurred.

The vulnerability lies in how iMessage automatically renders images. IMessage has been repeatedly targeted by NSO and other cyber arms dealers, prompting Apple to update its architecture. But that upgrade has not fully protected the system.

"Popular chat apps are at risk of becoming the soft underbelly of device security. Securing them should be top priority," said Citizen Lab researcher John Scott-Railton.

The US Cybersecurity and Infrastructure Security Agency had no immediate comment.

Citizen Lab said multiple details in the malware overlapped with prior attacks by NSO, including some that were never publicly reported. One process within the hack's code was named "setframed," the same name given in a 2020 infection of a device used by a journalist at Al Jazeera, the researchers found.

"The security of devices is increasingly challenged by attackers," said Citizen Lab researcher Bill Marczak.

A record number of previously unknown attack methods, which can be sold for $1 million or more, have been revealed this year. The attacks are labeled "zero-day" because software companies had zero days' notice of the problem.

Along with a surge in ransomware attacks against critical infrastructure, the explosion in such attacks has stoked a new focus on cybersecurity in the White House as well as renewed calls for regulation and international agreements to rein in malicious hacking.

The FBI has been investigating NSO, and Israel has set up a senior inter-ministerial team to assess allegations that its spyware has been abused on a global scale.

Although NSO has said it vets the governments it sells to, its Pegasus spyware has been found on the phones of activists, journalists and opposition politicians in countries with poor human rights records.

Top News / World+Biz

iPhone / software / cyber

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Around 99% of the cotton used in Bangladesh’s export and domestic garment production is imported. Photo: Collected
    NBR withdraws advance tax on imports of cotton, man-made fibres
  • The fire originated at 10:40pm on the 21th floor of the building. Photo: Collected
    Fire at Sena Kalyan Bhaban in Motijheel under control
  • Chief Adviser Professor Muhammad Yunus presided over a meeting of the National Consensus Commission at the State Guest House Jamuna yesterday (17 July). Photo: UNB
    CA Yunus stresses transparency in finalising July Charter

MOST VIEWED

  • Bangladesh Bank buys $313m more in second dollar auction in three days
    Bangladesh Bank buys $313m more in second dollar auction in three days
  • Representational image. File Photo: Syed Zakir Hossain/TBS
    Malaysia grants Bangladeshi workers multiple-entry visas
  • The Chattogram Custom House building in Chattogram. File Photo: Collected
    Software slowdown disrupts customs operations nationwide
  • NCP leaders are seen getting on an armoured personnel carrier (APC) of the army to leave Gopalganj following attacks on their convoy after the party's rally in the district today (16 july). Photo: Focus Bangla
    NCP leaders leave Gopalganj in army's APC following attack on convoy, clashes between AL, police
  • Renata’s manufacturing standards win european recognition
    Renata’s manufacturing standards win european recognition
  • The supporters of local Awami League and Chhatra League locked in a clash with police following attacks on NCP convoy this afternoon (16 July). Photo: Collected
    Gopalganj under curfew; 4 killed as banned AL, police clash after attack on NCP leaders

Related News

  • Software slowdown disrupts customs operations nationwide
  • FaceTime in iOS 26 will pause video calls if sensitive content detected
  • Proton ecosystem review: A privacy-first alternative to big tech
  • Foxconn sends 97% of India iPhone exports to US as Apple tackles Trump's tariffs
  • From Dhaka to Paris: How Kaz Software is making its place on global stage

Features

Illustration: TBS

20 years of war, 7.5m tonnes of bombs, 1.3m dead: How the US razed Vietnam to the ground

1h | The Big Picture
On 17 July 2024, Dhaka University campus became a warzone with police firing tear shells and rubber bullets to control the student movement. File Photo: Rajib Dhar/TBS

17 July 2024: Students oust Chhatra League from campuses, Hasina promises 'justice' after deadly crackdown

9h | Panorama
Abu Sayeed spread his hands as police fired rubber bullets, leading to his tragic death. Photos: Collected

How Abu Sayed’s wings of freedom ignited the fire of July uprising

2d | Panorama
Illustration: TBS

Open source legal advice: How Facebook groups are empowering victims of land disputes

3d | Panorama

More Videos from TBS

Why the conflicting claims over Gopalganj autopsies?

Why the conflicting claims over Gopalganj autopsies?

2h | TBS Stories
Gopalganj violence in international media

Gopalganj violence in international media

3h | TBS World
The Philippines has become a laboratory for China's disinformation propaganda

The Philippines has become a laboratory for China's disinformation propaganda

3h | TBS World
Gopalganj clash: Army urges not to be misled by rumors

Gopalganj clash: Army urges not to be misled by rumors

5h | TBS Today
EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Advertisement
  • Privacy Policy
  • Comment Policy
Copyright © 2025
The Business Standard All rights reserved
Technical Partner: RSI Lab

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net