London Daily

Focus on the big picture.
Sunday, Aug 02, 2026

Apple Fixes One of the iPhone's Most Pressing Security Risks

Apple Fixes One of the iPhone's Most Pressing Security Risks

By hardening iMessage in iOS 14, the company has effectively cut off what had been an increasingly popular line of attack.
Apple's iOS operating system is generally considered secure, certainly enough for most users most of the time. But in recent years hackers have successfully found a number of flaws that provide entry points into iPhones and iPads. Many of these have been what are called zero-click or interactionless attacks that can infect a device without the victim so much as clicking a link or downloading a malware-laced file.

Time and again these weaponized vulnerabilities turned out to be in Apple's chat app, iMessage. But now it appears that Apple has had enough. New research shows that the company took iMessage's defenses to a whole other level with the release of iOS 14 in September.

At the end of December, for example, researchers from the University of Toronto’s Citizen Lab published findings on a hacking campaign from the summer in which attackers successfully targeted dozens of Al Jazeera journalists with a zero-click iMessages attack to install NSO Group's notorious Pegasus spyware. Citizen Lab said at the time that it didn't believe iOS 14 was vulnerable to the hacking used in the campaign; all the victims were running iOS 13, which was current at the time.

Samuel Groß has long investigated zero-click iPhone attacks alongside a number of his colleagues at Google's Project Zero bug-hunting team. The week, he detailed three improvements that Apple added to iMessage to harden the system and make it much more difficult for attackers to send malicious messages crafted to wreak strategic havoc.

“These changes are probably very close to the best that could’ve been done given the need for backward compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole,” Groß wrote on Thursday. “It’s great to see Apple putting aside the resources for these kinds of large refactorings to improve end users’ security.”

In response to Citizen Lab's research, Apple said in December that “iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks.”

iMessage is an obvious target for zero-click attacks for two reasons. First, it's a communication system, meaning part of its function is to exchange data with other devices. iMessage is literally built for interactionless activity; you don't need to tap anything to receive a text or photo from a contact. And iMessage's full suite of features—integrations with other apps, payment functionality, even small things like stickers and memoji—make it fertile ground for hackers as well. All those interconnections and options are convenient for users but add “attack surface,” or potential for weakness.

“iMessage is a built-in service on every iPhone, so it’s a huge target for sophisticated hackers,” says Johns Hopkins cryptographer Matthew Green. “It also has a ton of bells and whistles, and every single one of those features is a new opportunity for hackers to find bugs that let them take control of your phone. So what this research shows is that Apple knows this and has been quietly hardening the system.”

Groß outlines three new protections Apple developed to deal with its iMessage security issues at a structural level, rather than through Band-Aid patches. The first improvement, dubbed BlastDoor, is a “sandbox,” essentially a quarantine zone where iMessage can inspect incoming communications for potentially malicious attributes before releasing them into the main iOS environment.

The second new mechanism monitors for attacks that manipulate a shared cache of system libraries. The cache changes addresses within the system at random to make it harder to access maliciously. iOS only changes the address of the shared cache after a reboot, though, which has given zero-click attackers an opportunity to discover its location; it's like taking shots in the dark until you hit something. The new protection is set up to detect malicious activity and trigger a refresh without the user having to restart their iPhone.

The final addition makes it more difficult for hackers to “brute force,” or retry attacks multiple times—a common technique in zero-click hacks if an assault doesn't quite work the first time. This protection is relevant to reducing those shots in the dark to find the shared cache, but also to attacks more broadly, like attempts to send multiple malicious texts (which are typically invisible to the user) to retry an attack until it works.

Independent researchers agree with Groß's assessment that the version of iMessage in iOS 14 is much better defended against these types of attacks.

“The mitigations are very welcome and appear to be intelligently done,” says Will Strafach, a longtime iOS researcher and creator of the Guardian Firewall app for iOS. “I would have hoped to see something like this sooner as iMessage is a big target for remote attacks, but it at least looks like they put a decent amount of care into this.”

Now that they're here, the improvements should make a big difference in curbing the rising tide of interactionless attacks against iMessage. But researchers warn that it's only a matter of time before attackers find a new spin on their stalwart techniques.
Newsletter

Related Articles

0:00
0:00
Close
Finland Deploys Commercial-Scale Thermal Batteries Using Crushed Rock to Store Renewable Grid Energy
Valued at $109 Million: F-35B Fighter Jet Crashes in Southern California
Sainsbury Agrees to Sell Argos in £120 Million Deal to Private Consortium
High Court Clears Way for Construction of Chinese Embassy at Royal Mint Court
UK Fuel Prices Climb to Multi-Month Highs as Strait of Hormuz Tensions Disrupt Oil Supplies
Severe Summer Drought and Record Heat Put UK Harvests at Risk
Prime Minister Andy Burnham Faces Labour Backbench Opposition Over Potential Support for New North Sea Oil and Gas Drilling
Bank of England Warns Inflation Will Stay Above 3% as Middle East Energy Shock Prolongs Cost-of-Living Pressures
Andy Burnham has Announces Plans to Redistribute Income Tax Revenue to English Mayors
Early-Release Scheme Faces Fresh Scrutiny as Reoffending and Prison Recalls Rise
Police Phone Checks Followed Report on Murder of MI5 Agent Inside Sinn Féin
Archbishop of Canterbury Reaffirms £100 Million Reparative Justice Fund During Ghana Visit
Charities Allege French Police Used Tear Gas Against Channel Migrants
Norwegian Teenager Convicted Over Iran-Linked Murder Plot in Britain
Christian Organisations File Charity Complaints Against Amnesty International UK
Ofgem Tightens Grid Connection Rules for New Data Centres
FTSE 100 Reaches Record High Despite Global Technology Sell-Off
Millions of UK Households Urged to Check Eligibility for Winter Energy Discount
Labour Restores Parliamentary Whips to Diane Abbott and Joani Reid
UK Supreme Court to Hear Challenge Over Palestine Action Ban
UK Commits More Than £8.4 Billion to Dreadnought Nuclear Submarine Programme
England Declares Severe Drought as Wildfire Burns Near Sizewell Nuclear Site
Bank of England Holds Interest Rates at 3.75% as Middle East Tensions Fuel Inflation Risks
Drought Status Extended Across All of Wales as Heat and Dry Weather Deepen Environmental Strain
Record-Low Danube Exposes Probable Mammoth Remains in Bulgaria
UK Business Confidence Climbs to Four-Month High
Greater Manchester Gains Expanded Powers Under Regional Funding Reforms
UK Supreme Court to Hear Appeal Over Palestine Action Terror Ban
Shell's Quarterly Profit Doubles to Nearly $10 Billion on Higher Energy Prices
UK Government Removes VAT From Household Electricity Bills
Exceptional Drought Grips Half of England as Wildfire Threatens Sizewell
Bank of England Holds Interest Rates at 3.75% as Inflation Risks Persist
US Says It Has Carried Out Heavy Strikes on Iran After Attempted Attacks on Its Forces
The chief executive of the popular gaming company laid off many employees and his pay rose to 38 million dollars
UK Employment Holds Steady as Wage Growth Remains Moderate
England to Introduce Artificial Intelligence into Secondary School Curriculum
Wales Launches £1.2 Billion Industrial Regeneration Programme
High Court Upholds UK Digital Surveillance Framework
Northern Ireland Reaches Budget Agreement on Infrastructure and Public Sector Pay
Home Office Expands Digital Border Checks Nationwide
UK Approves Major North Sea Wind and Carbon Capture Project
The World's Most Terrifying Smartphone: Recording, Documenting, and Reporting to the Regime
Scotland Approves Major Renewable Energy Expansion
UK and United States Sign AI and Semiconductor Cooperation Pact
UK Treasury Tightens Fiscal Controls After Gilt Market Volatility
Bank of England Holds Interest Rates at 4.5%
UK Unveils £10 Billion NHS Funding Overhaul and Workforce Reform
The AI User Nightmare: Private Claude Conversations Leaked to the Internet
UK: Former Football Association Leaders Call for World Cup Boycott Over FIFA Privatization Plan
Forbidden Love: China severs millions from their virtual partners
×