Google har hittat buggar i iOS som har exploaterats under flera år, bland annat av webbplatser där kod har installerats. Koden har injicerats och användare kan ha fått personlig information stulen.
Enligt Google så handlar det om ett mindre antal webbplatser som har kunnat att exploatera säkerhetshål i iOS enbart genom att de aktuella webbplatserna har besökts.
Earlier this year Google’s Threat Analysis Group (TAG) discovered a small collection of hacked websites. The hacked sites were being used in indiscriminate watering hole attacks against their visitors, using iPhone 0-day.
There was no target discrimination; simply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant. We estimate that these sites receive thousands of visitors per week.
TAG was able to collect five separate, complete and unique iPhone exploit chains, covering almost every version from iOS 10 through to the latest version of iOS 12. This indicated a group making a sustained effort to hack the users of iPhones in certain communities over a period of at least two years.


0 kommentarer