Google Uncovers Massive Multi-Year iPhone Hacking Campaign
Google researchers reveal that a series of hacked websites secretly infected thousands of iPhones over two years with highly invasive malware. The attack extracts sensitive data like passwords and messages, though Apple has since patched the vulnerabilities.
Google researchers uncover the largest known attack against iPhone users, revealing that a series of hacked websites secretly infect thousands of visitors over a period of at least two years. This watering-hole attack simply requires a user to visit a compromised site to automatically download malware, utilizing a chain of 14 vulnerabilities that includes at least one zero-day exploit.
Once installed, the malware operates silently in the background with no visual indicator, allowing hackers to ransack the entire device. The malicious program steals extremely sensitive information, including passwords, encrypted messages, location data, and contacts, before sending this data to a remote command and control server.
The unprecedented scale and sophistication of this campaign strongly suggest a nation-backed operation, though the exact identities of the hackers and their targets remain unknown. Apple eliminates these specific vulnerabilities with a February 2019 patch, meaning users who update their devices are fully protected, even though rebooting an infected device only wipes the malware after the data is already stolen.