+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Google researchers found a bunch of malicious sites that quietly hacked iPhones for years

Aug 30, 2019, 15:50 IST

FILE PHOTO: A attendee uses a new iPhone X during a presentation for the media in BeijingReuters

Advertisement
  • Researchers at Google's cybersecurity division Project Zero discovered a handful of websites that were being used to hack iPhones.
  • Once visited, the websites would plant a "monitoring implant" on the device, which could then steal messages, photos, and real-time GPS location data.
  • The hacks spanned iOS 10 through 12, which Project Zero said indicates they took place over the course of two years.
  • Visit Business Insider's homepage for more stories.

Google researchers found a handful of hacked websites that were being quietly used to infiltrate iPhones for at least the last two years.

Analysts at Google's cybersecurity division Project Zero published a deep-dive technical blog Thursday night detailing their findings.

Complimentary Tech Event
Transform talent with learning that works
Capability development is critical for businesses who want to push the envelope of innovation.Discover how business leaders are strategizing around building talent capabilities and empowering employee transformation.Know More

"There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant," security researcher Ian Beer wrote in the blog. Once inside the iPhone, this implant was able to steal messages, photos, and GPS location data in real-time.

Although the blog post didn't say exactly how many of these websites they were, the researchers estimated each one received thousands of visitors a week. The hacks spanned iOS 10 through 12, which Beer said indicated a "sustained effort" to hack iPhones over a period of two years.

Advertisement

Read more: Apple accidentally reopened a security flaw that makes the iPhone vulnerable to hackers

The websites gained access to the iPhones through five different methods or "exploit chains." The researchers found 14 separate vulnerabilities which made these exploit chains possible. Seven of these vulnerabilities were found in Safari, iPhones' default web browser.

The researchers told Apple about their findings in February, and gave the company a seven-day deadline to fix the vulnerabilities. Six days later, Apple updated the security on iOS 12. Google gave Apple a much tighter deadline than is usual in security disclosure, which the norm being 90 days to patch issues.

Generally Apple has a strong reputation when it comes to security, and earlier this month the company upped the amount of money it's willing to shell out for bug bounties - vulnerabilities found by security researchers - to $1 million.

Apple declined to comment when contacted by Business Insider.

Advertisement

NOW WATCH: If you want an emoji that isn't available, you can create it. Here's how everyday people send their submissions.

Next Article