Apple says NSO’s ‘Pegasus’ zero-click iMessage exploit not a threat to the overwhelming majority of users

Amnesty International on Sunday detailed highly-targeted attacks towards specific human rights lawyers, journalists, and/or activists using Apple’s iMessage to deliver the targeted zero-click attacks. Apple provided a statement to The Washington Post.The attack is sold by Israeli firm NSO Group as “Pegasus.”

bitsAmnesty International:

Amnesty believes Pegasus spyware is currently being delivered using a zero-click iMessage exploit that works against iPhone and iPad devices running iOS 14.6. The exploit also appeared to successfully work against iPhones running iOS 14.3 and iOS 14.4.

Ivan Krstić, head of Apple Security Engineering and Architecture, has commented on the matter.

The Washington Post:

Apple unequivocally condemns cyberattacks against journalists, human rights activists, and others seeking to make the world a better place. For over a decade, Apple has led the industry in security innovation and, as a result, security researchers agree iPhone is the safest, most secure consumer mobile device on the market. Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals. While that means they are not a threat to the overwhelming majority of our users, we continue to work tirelessly to defend all our customers, and we are constantly adding new protections for their devices and data.

MacDailyNews Take: Further bolstering of iMessage security coming soon, we imagine – if they haven’t already begin to arrive with Monday’s release of iOS 14.7 and iPadOS 14.7.

12 Comments

  1. One might consider ridding the planet of the only species that produces compounds toxic not only to members of that species but to all other living species on the planet as making the world a better place. Food for thought.

      1. Since 99.9% of those currently dying of COVID are unvaccinated, it sounds like we are weeding out some of the unfit. Unfortunately, they are also risking innocent bystanders.

        1. THAT is misinformation…. that figure is based on a report by the AP that did a so-called analysis of CDC data…BUT it lacks so much context….when examined closely there is so much wrong with this report…BUT it is getting parroted with little scrutiny…

          Start with:
          “The AP came up with these numbers using CDC data. The CDC tracks the numbers of cases, hospitalizations and deaths, but does not break down rates by vaccination status.”
          So how could they perform their calculation? Just on that alone should show that this “report” is unsubstantiated.

          There are reports that the CDC has also stopped fully tracking the number of COVID cases amount the vaccinated. This follows through to a lot of medical facilities that do likewise… This creates SO MUCH confounding of the data that it is meaningless…
          – how many in the study were actually FULLY vaccinated?
          – how many vaccinated people are even tested for COVID?
          – how many vaccinated COVID cases are no longer associated with the patient outcome (hospitalization or death)?

          Then there is the issue of CONTEXT! The study was done in “May” but being reported in late June. There is NO context of which days in May. Even if it were the entire month, vaccination rates were still VERY low… peaking at about 20% in LATE MAY but only around 10% in early MAY, meaning that MANY cases were NOT vaccinated because few people were, so OF COURSE mostly “unvaccinated” died… AND the report states that the “unvaccinated” refers to those also only receiving one shot…

          BUT how does all this get reported? “It seems compelling, even for skeptics, that unvaccinated people represent 99% of those now dying from COVID-19, when they represent less than 50% of the adult population in the USA.”
          BUT the fact is that the over 50% vaccination rate is NOW, NOT when the “report” was done.

          And there is MORE wrong with this “report”.

          THIS IS FAKE NEWS!!!

          If that is not manipulation of the data and people, I do not know what is.

          Anyway, this is NOTHING to do with the OP.

        2. Get your facts straight. The article was only discussing the 117 people in the UK who have died of the Delta variant, 50 of whom were fully vaccinated and the rest partially or completely unvaccinated. As the article itself says, that is not surprising because there are very few unvaccinated adults in the UK over 65 or with a serious health issue. That is why their 7-day average of Covid deaths is currently 40 among a population of 68.2 million, while the average is 14 in Missouri with 6 million people. Britain has a lot more people per capita testing positive, but a lot fewer dying.

        3. @TxUser your comment adds nothing to the conversation to offset the original comments… this is just diversionary… but that is your forte…

  2. Overwhelming majority of users are not going to be targeted by NSO software anyway. Only those of interest to governments will be. So Apple’s statement is a non-denial denial.

    Cupertino, we have a problem!

  3. “Apple unequivocally condemns cyberattacks against journalists, human rights activists, and others seeking to make the world a better place.”

    What about the rest of the world? Or is it only those that Apple deems “worthy” to be defended?

  4. Hey, vaccine scaredy-cats…
    I run anti-virus software. Even though vaccines don’t even exist. Supposedly.
    Will I die? Or maybe become a Microsoft robot?
    I’m so SCARED 🙄

Reader Feedback

This site uses Akismet to reduce spam. Learn how your comment data is processed.