London Daily

Focus on the big picture.
Saturday, Sep 12, 2026

Apple Fixes One of the iPhone's Most Pressing Security Risks

Apple Fixes One of the iPhone's Most Pressing Security Risks

By hardening iMessage in iOS 14, the company has effectively cut off what had been an increasingly popular line of attack.
Apple's iOS operating system is generally considered secure, certainly enough for most users most of the time. But in recent years hackers have successfully found a number of flaws that provide entry points into iPhones and iPads. Many of these have been what are called zero-click or interactionless attacks that can infect a device without the victim so much as clicking a link or downloading a malware-laced file.

Time and again these weaponized vulnerabilities turned out to be in Apple's chat app, iMessage. But now it appears that Apple has had enough. New research shows that the company took iMessage's defenses to a whole other level with the release of iOS 14 in September.

At the end of December, for example, researchers from the University of Toronto’s Citizen Lab published findings on a hacking campaign from the summer in which attackers successfully targeted dozens of Al Jazeera journalists with a zero-click iMessages attack to install NSO Group's notorious Pegasus spyware. Citizen Lab said at the time that it didn't believe iOS 14 was vulnerable to the hacking used in the campaign; all the victims were running iOS 13, which was current at the time.

Samuel Groß has long investigated zero-click iPhone attacks alongside a number of his colleagues at Google's Project Zero bug-hunting team. The week, he detailed three improvements that Apple added to iMessage to harden the system and make it much more difficult for attackers to send malicious messages crafted to wreak strategic havoc.

“These changes are probably very close to the best that could’ve been done given the need for backward compatibility, and they should have a significant impact on the security of iMessage and the platform as a whole,” Groß wrote on Thursday. “It’s great to see Apple putting aside the resources for these kinds of large refactorings to improve end users’ security.”

In response to Citizen Lab's research, Apple said in December that “iOS 14 is a major leap forward in security and delivered new protections against these kinds of attacks.”

iMessage is an obvious target for zero-click attacks for two reasons. First, it's a communication system, meaning part of its function is to exchange data with other devices. iMessage is literally built for interactionless activity; you don't need to tap anything to receive a text or photo from a contact. And iMessage's full suite of features—integrations with other apps, payment functionality, even small things like stickers and memoji—make it fertile ground for hackers as well. All those interconnections and options are convenient for users but add “attack surface,” or potential for weakness.

“iMessage is a built-in service on every iPhone, so it’s a huge target for sophisticated hackers,” says Johns Hopkins cryptographer Matthew Green. “It also has a ton of bells and whistles, and every single one of those features is a new opportunity for hackers to find bugs that let them take control of your phone. So what this research shows is that Apple knows this and has been quietly hardening the system.”

Groß outlines three new protections Apple developed to deal with its iMessage security issues at a structural level, rather than through Band-Aid patches. The first improvement, dubbed BlastDoor, is a “sandbox,” essentially a quarantine zone where iMessage can inspect incoming communications for potentially malicious attributes before releasing them into the main iOS environment.

The second new mechanism monitors for attacks that manipulate a shared cache of system libraries. The cache changes addresses within the system at random to make it harder to access maliciously. iOS only changes the address of the shared cache after a reboot, though, which has given zero-click attackers an opportunity to discover its location; it's like taking shots in the dark until you hit something. The new protection is set up to detect malicious activity and trigger a refresh without the user having to restart their iPhone.

The final addition makes it more difficult for hackers to “brute force,” or retry attacks multiple times—a common technique in zero-click hacks if an assault doesn't quite work the first time. This protection is relevant to reducing those shots in the dark to find the shared cache, but also to attacks more broadly, like attempts to send multiple malicious texts (which are typically invisible to the user) to retry an attack until it works.

Independent researchers agree with Groß's assessment that the version of iMessage in iOS 14 is much better defended against these types of attacks.

“The mitigations are very welcome and appear to be intelligently done,” says Will Strafach, a longtime iOS researcher and creator of the Guardian Firewall app for iOS. “I would have hoped to see something like this sooner as iMessage is a big target for remote attacks, but it at least looks like they put a decent amount of care into this.”

Now that they're here, the improvements should make a big difference in curbing the rising tide of interactionless attacks against iMessage. But researchers warn that it's only a matter of time before attackers find a new spin on their stalwart techniques.
Newsletter

Related Articles

0:00
0:00
Close
Chinese Crypto Entrepreneur Leon Li Identified as Seller of £190 Million London Mansion
Trades Union Congress Proposes Social Energy Tariff Funded by Higher Bank Surcharge
British Chambers of Commerce Calls for State Pension Triple Lock to Be Scrapped
Anthropic Says Claude Helped Disrupt Biological Weapons and Cyber Espionage Threats
UK Imposes Sanctions Over Israeli Settlements and West Bank Violence
UK Reimposes Sectoral Sanctions on Iran’s Aviation, Shipping and Energy Networks
UK Economy Grows 0.4% in July as AI and Programming Services Lift Activity
UK House of Commons Rejects Assisted Dying Bill by 286 Votes to 270
UK Reviews Nationwide Emergency Alert Tests After Systems Meet Reliability Targets
UK Seeks Faster Rail Links Across Northern Industrial Corridors
British Business Bank Allocates £150 Million for High-Growth Companies in Northern England
BBC Warns Staff Strikes Are Possible Amid Pay Dispute and £500 Million Savings Drive
UK Backs Short Extension of UN Sudan Sanctions Regime
Prime Minister Andy Burnham Defends Early Prison Release Reforms and Growth Strategy
Reform UK Faces Scrutiny Over Alleged Effort to Circumvent Foreign Donation Rules
UK Analysts Warn Tax Rises or Spending Cuts May Be Needed to Preserve Fiscal Headroom
Jaguar Land Rover Plans Up to 4,000 Job Cuts in £1.7 Billion Cost-Saving Drive
UK Chancellor Warns of Difficult October Budget as Borrowing Costs Rise
UK Declares Israeli Occupation of West Bank Unlawful and Expands Sanctions
UK House of Commons Rejects Assisted Dying Bill for England and Wales
English Councils to Gain Power to Introduce Tourist Taxes by 2028
Kemi Badenoch Reshuffles Conservative Shadow Cabinet
Firefighters Make Progress Containing Major Wildfires in South Wales
John Lewis Partnership Reports £124 Million Loss
Study Says UK AI Data Centres Will Create Only a Quarter of Forecast Jobs
UK Government Considers Higher Industrial Water Prices Amid Supply Pressures
Andy Burnham Holds First Call With Donald Trump as UK Prime Minister
NHS Records Busiest Summer on Record as Heatwaves Drive Hospital Admissions
Home Secretary Orders Police Crackdown on Far-Right Anti-Migrant Vigilantes
UK Supreme Court Rules Northern Ireland Religious Education Curriculum Breaches Human Rights Standards
Markets Price in Four Bank of England Rate Rises by Next Summer
House of Commons Prepares Free Vote on Assisted Dying Bill
UK Government Bans Trade With Israeli Settlements in Occupied Territories
UK Economy Grows 0.4% in July as Artificial Intelligence Investment Supports Expansion
Andy Burnham Becomes UK Prime Minister After Keir Starmer Resigns
John Lewis Partnership Loss Widens to £124 Million
UK Government to Put White Working-Class Social Mobility at Centre of Equality Policy
McLaren Plans £450 Million Technology Investment Creating 1,000 UK Jobs
UK Chancellor Faces Calls for Wealth Taxes and Public Ownership in Autumn Budget
English Mayors to Gain Powers to Impose Uncapped Overnight Tourist Taxes
JPMorgan’s Jamie Dimon Warns UK Government Against Bank Windfall Taxes
UK Air Traffic Control Outage Cancels More Than 2,000 Flights
UK Imposes Trade Ban on Israeli Settlements in the West Bank
UK Borrowing Costs Surge as Middle East Tensions Push Long-Term Gilt Yields to Highest Since 1998
Buckingham Palace Says Prince Harry and Meghan Will Not Resume Official Royal Duties
UK Treasury Faces Calls to Scrap £100,000 Childcare Support Threshold
Trades Union Congress Urges Labour Government to Rewrite Migration Policy
Riot Police Deployed After Anti-Migrant Protests Turn Violent in Portsmouth
UK Considers Replacing Some Disability Cash Payments With Direct Services
JPMorgan’s Jamie Dimon Warns UK Chancellor Against Higher Banking Taxes
×