{"id":19250,"date":"2021-09-15T00:18:45","date_gmt":"2021-09-15T00:18:45","guid":{"rendered":"https:\/\/www.esecurityplanet.com\/?p=19250"},"modified":"2021-09-15T00:18:45","modified_gmt":"2021-09-15T00:18:45","slug":"apple-patches-ios-spyware-vulnerabilities","status":"publish","type":"post","link":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/","title":{"rendered":"Apple Patches Vulnerabilities in iOS Exploited by Spyware"},"content":{"rendered":"<p>Apple continues to be haunted by spyware developed by an Israeli security firm that hostile governments used to hack into Apple devices to spy on journalists, activists and world leaders (see <a href=\"https:\/\/www.esecurityplanet.com\/mobile\/apple-security-nso-spyware-scandal\/\">Apple Security Under Scrutiny Amid Fallout from NSO Spyware Scandal<\/a>).<\/p>\n<p>News of the nefarious uses of NSO Group&#8217;s Pegasus software first surfaced in July. Apple was notified earlier this month by researchers with Citizen Lab \u2013 an internet security watchdog group based at the University of Toronto \u2013 that a <a href=\"https:\/\/www.esecurityplanet.com\/threats\/zero-day-threat\/\">zero-day vulnerability<\/a> in its iOS 14.8 and iPadOS 14.8 operating system was being exploited by the invasive Pegasus spyware. The exploit impacts every iPhone, iPad, Mac and Apple Watch.<\/p>\n<p>Apple this week released <a href=\"https:\/\/support.apple.com\/en-us\/HT201222\">security updates<\/a> for its devices that will close the vulnerability that Pegasus exploited. In a <a href=\"https:\/\/support.apple.com\/en-us\/HT212807\">security note<\/a>, the company said that \u201cprocessing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.\u201d<\/p>\n<h2>Spyware Vulnerability<\/h2>\n<p>The Pegasus spyware has been an ongoing source of controversy. Users of the spyware are able to extract data \u2013 including emails, messages and photos \u2013 from devices and also can record calls and activate microphones and cameras.<\/p>\n<p>According to a <a href=\"https:\/\/citizenlab.ca\/2021\/09\/forcedentry-nso-group-imessage-zero-click-exploit-captured-in-the-wild\/\">report<\/a> by Citizen Lab researchers, they were analyzing the phone of a Saudi activist that they soon determined had been infected with Pegasus. During the investigation, the researchers discovered a zero-day, zero-click exploit against iMessage, which they dubbed \u201cForcedEntry.\u201d The exploit \u2013 labeled CVE-2021-30860 \u2013 targets an integer overflow vulnerability in Apple\u2019s CoreGraphics image rendering library, they wrote.<\/p>\n<p>The researchers suspect ForcedEntry has been in use since at least February. It doesn\u2019t require users to click on fraudulent links or open malicious files to infect a device. The researchers urged users of the devices to download the fixes.<\/p>\n<h2>Fast Fixes by Apple<\/h2>\n<p>Citizen Lab contacted Apple about ForcedEntry Sept. 7, and less than a week later the vendor issued the fixes.<\/p>\n<p>In a statement, Ivan Krstic, head of security engineering and architecture operations at Apple, thanked Citizen Lab for sending a sample of the exploit to the company, enabling it to issue a fix.<\/p>\n<p>&#8220;Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals,&#8221; Krstic said. &#8220;While that means they are not a threat to the overwhelming majority of our users, we continue to work tirelessly to defend all our customers, and we are constantly adding new protections for their devices and data.&#8221;<\/p>\n<p>NSO Group, which was founded in 2010, over the years has pushed back at criticism of Pegasus and its other software products, arguing that the technology is a tool to enable governments to protect themselves and their citizens against terrorists and other criminals. In a brief statement this week, officials made the same argument, adding that the company will \u201ccontinue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime.&#8221;<\/p>\n<h2>NSO Group Faces Skeptics<\/h2>\n<p>However, cybersecurity professionals see the company\u2019s arguments as ways to deflect criticism.<\/p>\n<p>\u201cNSO has maintained the stance that the spyware is only sold to a handful of intelligence communities within countries that have been thoroughly vetted for human rights violations,\u201d Hank Schless, senior manager of security solutions for cybersecurity firm Lookout, told <em>eSecurity Planet<\/em>. \u201cTheir proactive statements about the Citizen Lab is just another attempt at maintaining this narrative in the media.\u00a0The recent exposure of 50,000 phone numbers linked to targets of NSO Group customers was all people needed to see right through what NSO claims.\u201d<\/p>\n<p>In July, <em>The Guardian<\/em> <a href=\"https:\/\/www.theguardian.com\/world\/2021\/jul\/18\/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus\">reported<\/a> a large data leak that unveiled a list of more than 50,000 iPhone numbers of people being watched by NSO customers dating back to 2016. More than 180 journalists worldwide were caught up in the leak and the report suggested that some Pegasus users like authoritarian regimes were using Pegasus to track people who weren\u2019t criminals or terrorists.<\/p>\n<p>Amnesty International and Forbidden Stories\u00a0\u2013 a Paris-based nonprofit group that works with journalists \u2013\u00a0<a href=\"https:\/\/www.amnesty.org\/en\/latest\/trends\/2021\/07\/pegasus-project-apple-iphones-compromised-by-nso-spyware\/\">said<\/a> Pegasus users were able to hack into iPhone 11 and iPhone 12 devices,\u00a0as well as Android devices.<\/p>\n<h2>&#8216;Despotism-as-a-service&#8217;<\/h2>\n<p>Kevin Dunne, president of access orchestration solutions company Pathlock, noted that enterprises also need to worry about the threat posed by spyware such as Pegasus, particularly given the highly distributed and mobile IT environment.<\/p>\n<p>\u201cBusinesses often focus on their servers and workstations as the primary targets for hacking and espionage,\u201d Dunne told <em>eSecurity Planet<\/em>. \u201cHowever, mobile devices are now used broadly and contain sensitive information that needs to be protected.\u00a0Spyware is primarily targeting these mobile devices and providing critical information to unauthorized parties.\u201d<\/p>\n<p>Citizen Lab researchers said ForcedEntry isn\u2019t the first zero-click exploit linked to NSO. In 2019, WhatsApp was forced to fix a zero-click vulnerability in the WhatsApp calling feature that NSO clients used against more than 1,400 phones over a two-week period in which it was observed. Apple in iOS 14 introduced the BlastDoor mitigation, and the researchers suspect that NSO developed ForedEntry to circumvent BlastDoor.<\/p>\n<p>\u201cOur latest discovery of yet another Apple zero day employed as part of NSO Group\u2019s arsenal further illustrates that companies like NSO Group are facilitating \u2018despotism-as-a-service\u2019 for unaccountable government security agencies,\u201d they wrote. \u201cRegulation of this growing, highly profitable, and harmful marketplace is desperately needed.\u201d<\/p>\n<h2>Messaging Apps a Growing Target<\/h2>\n<p>The researchers also cautioned organizations to understand the growing threats presented via chat and messaging apps.<\/p>\n<p>\u201cOur finding also highlights the paramount importance of securing popular messaging apps,\u201d they wrote. \u201cUbiquitous chat apps have become a major target for the most sophisticated threat actors, including nation state espionage operations and the mercenary spyware companies that service them. As presently engineered, many chat apps have become an irresistible soft target. Without intense engineering focus, we believe that they will continue to be heavily targeted, and successfully exploited.\u201d<\/p>\n<p>The issues around the security update, Pegasus and NSO come just as Apple was preparing to roll out a spate of new products, including the latest iPhones, iPads and Apple Watches. Even the release of new products generated its own controversy, as protestors and privacy rights groups like the Electronic Frontier Foundation (EFF) gathered outside of Apple stores around the United States Aug. 13 to push back at Apple\u2019s Child Sexual Abuse Material (CSAM) system that searches iCloud for such material. A plan to put it into iOS 15 has been delayed.<\/p>\n<p>Further reading: <a href=\"https:\/\/www.esecurityplanet.com\/mobile\/mobile-malware-threats-and-solutions\/\">Mobile Malware: Threats and Solutions<\/a><\/p>\n\n\n<div id=\"ta-campaign-widget-66d7021fe0c8f-popup-wrapper\" class=\"ta-campaign-widget__popup-wrapper\">\n    \n<div\n    style=\"\n        --ta-campaign-plugin-primary: #3545ed;\n        --ta-campaign-plugin-button-text: #fff;\n        --ta-campaign-plugin-button-hover-background: #3231b4;\n        --ta-campaign-plugin-button-hover-text: #fff;\n        --ta-campaign-plugin-button-toggle-background: #3231b4;\n        --ta-campaign-plugin-button-toggle-text: #3231B4;\n    \"\n    data-ajax-url=\"https:\/\/www.esecurityplanet.com\/wp\/wp-admin\/admin-ajax.php\">\n    <div\n        id=\"ta-campaign-widget-66d7021fe0c8f\"\n        class=\"ta-campaign-widget ta-campaign-widget--popup\"\n        data-campaign-fields='{\"properties\":{\"campaign_type\":\"popup\",\"campaign_category\":false,\"sailthru_list\":[\"cybersecurity-insider\"],\"popup_type\":\"exit_intent\",\"appearance\":{\"colors\":{\"primary_color\":\"#3545ed\",\"button\":{\"button_text_color\":\"#fff\",\"hover\":{\"button_hover_background_color\":\"#3231b4\",\"button_hover_text_color\":\"#fff\"},\"toggle\":{\"button_toggle_background_color\":\"#3231b4\",\"button_toggle_text_color\":\"#3231B4\"}}},\"custom_scss\":\"\"},\"behavior\":{\"opt_in_enabled\":true},\"language\":{\"tagline\":\"Get the Free Cybersecurity Newsletter\",\"subtagline\":\"\",\"content\":\"Strengthen your organization&#39;s IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday\",\"email_placeholder\":\"Work Email Address\",\"opt_in\":\"By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.\",\"subscribe_button\":\"Subscribe\"}},\"identifier\":\"66d7021fe0c8f\",\"campaign_id\":26045,\"campaign_type\":\"popup\",\"popup_type\":\"exit_intent\",\"newsletters\":[\"cybersecurity-insider\"],\"behavior\":{\"opt_in_enabled\":true},\"appearance\":{\"colors\":{\"primary\":\"#3545ed\",\"button\":{\"text\":\"#fff\",\"hover\":{\"background\":\"#3231b4\",\"text\":\"#fff\"},\"toggle\":{\"background\":\"#3231b4\",\"text\":\"#3231B4\"}}},\"custom_css\":\"\"},\"language\":{\"tagline\":\"Get the Free Cybersecurity Newsletter\",\"subtagline\":\"\",\"content\":\"Strengthen your organization&#39;s IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday\",\"email_placeholder\":\"Work Email Address\",\"opt_in\":\"By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.\",\"subscribe_button\":\"Subscribe\"}}'>\n\n                <div class=\"ta-campaign-widget__exit\">\n            <svg class=\"w-8\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"1.5\" viewBox=\"0 0 24 24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" aria-hidden=\"true\">\n                <path stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M6 18L18 6M6 6l12 12\"><\/path>\n            <\/svg>\n        <\/div>\n        \n        <div class=\"ta-campaign-widget__wrapper\">\n            <div class=\"ta-campaign-widget__header mb-6\">\n                                <h3 class=\"ta-campaign-widget__tagline\">\n                    Get the Free Cybersecurity Newsletter                <\/h3>\n                \n                \n                                <p class=\"ta-campaign-widget__content mt-6\">\n                    Strengthen your organization's IT security defenses by keeping up to date on the latest cybersecurity news, solutions, and best practices. Delivered every Monday, Tuesday and Thursday                <\/p>\n                            <\/div>\n\n            <form class=\"ta-campaign-widget__form\">\n                <div class=\"ta-campaign-widget__input mb-4\"  data-field=\"email\">\n                    <label\n                        class=\"sr-only\"\n                        for=\"email-66d7021fe0c8f\">\n                        Email Address\n                    <\/label>\n                    <input\n                        class=\"ta-campaign-widget__input__text\"\n                        placeholder=\"Work Email Address\"\n                        id=\"email-66d7021fe0c8f\"\n                        name=\"email\"\n                        type=\"email\">\n                <\/div>\n\n                                <div class=\"ta-campaign-widget__checkbox mb-4\" data-field=\"opt_in\">\n                    <div class=\"flex items-start\">\n                        <input\n                            id=\"opt-in-66d7021fe0c8f\"\n                            class=\"ta-campaign-widget__checkbox__input mr-2\"\n                            name=\"opt-in\"\n                            type=\"checkbox\"\/>\n                        <label\n                            class=\"ta-campaign-widget__checkbox__label\"\n                            for=\"opt-in-66d7021fe0c8f\">\n                            By signing up to receive our newsletter, you agree to our Terms of Use and Privacy Policy. You can unsubscribe at any time.                        <\/label>\n                    <\/div>\n                <\/div>\n                \n                <button class=\"ta-campaign-widget__button\" type=\"submit\" >\n                    Subscribe                <\/button>\n            <\/form>\n        <\/div>\n    <\/div>\n<\/div>\n\n<style>\n<\/style><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Apple continues to be haunted by spyware developed by an Israeli security firm that hostile governments used to hack into Apple devices to spy on journalists, activists and world leaders (see Apple Security Under Scrutiny Amid Fallout from NSO Spyware Scandal). News of the nefarious uses of NSO Group&#8217;s Pegasus software first surfaced in July. [&hellip;]<\/p>\n","protected":false},"author":256,"featured_media":18859,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_gazelle_contributing_experts":"","footnotes":""},"categories":[23,15],"tags":[18145,627,4813],"b2b_audience":[33],"b2b_industry":[],"b2b_product":[378,379,396],"class_list":["post-19250","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-threats","tag-cyber-threats-2","tag-data-privacy","tag-spyware","b2b_audience-awareness-and-consideration","b2b_product-endpoint-security","b2b_product-threats-and-vulnerabilities","b2b_product-wireless-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Apple Patches Vulnerabilities in iOS Exploited by Spyware | eSecurity Planet<\/title>\n<meta name=\"description\" content=\"NSO Group&#039;s Pegasus spyware continues to target Apple devices, and privacy and human rights advocates grow increasingly concerned.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple Patches Vulnerabilities in iOS Exploited by Spyware | eSecurity Planet\" \/>\n<meta property=\"og:description\" content=\"NSO Group&#039;s Pegasus spyware continues to target Apple devices, and privacy and human rights advocates grow increasingly concerned.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\" \/>\n<meta property=\"og:site_name\" content=\"eSecurity Planet\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-15T00:18:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"626\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jeff Burt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@eSecurityPlanet\" \/>\n<meta name=\"twitter:site\" content=\"@eSecurityPlanet\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Burt\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\"},\"author\":{\"name\":\"Jeff Burt\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/62368dee45ce8f1ffc35abf9f8cc854e\"},\"headline\":\"Apple Patches Vulnerabilities in iOS Exploited by Spyware\",\"datePublished\":\"2021-09-15T00:18:45+00:00\",\"dateModified\":\"2021-09-15T00:18:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\"},\"wordCount\":1079,\"publisher\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg\",\"keywords\":[\"cyber threats\",\"Data privacy\",\"spyware\"],\"articleSection\":[\"Compliance\",\"Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\",\"url\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\",\"name\":\"Apple Patches Vulnerabilities in iOS Exploited by Spyware | eSecurity Planet\",\"isPartOf\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg\",\"datePublished\":\"2021-09-15T00:18:45+00:00\",\"dateModified\":\"2021-09-15T00:18:45+00:00\",\"description\":\"NSO Group's Pegasus spyware continues to target Apple devices, and privacy and human rights advocates grow increasingly concerned.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg\",\"width\":1200,\"height\":626,\"caption\":\"spyware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.esecurityplanet.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple Patches Vulnerabilities in iOS Exploited by Spyware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#website\",\"url\":\"https:\/\/www.esecurityplanet.com\/\",\"name\":\"eSecurity Planet\",\"description\":\"Industry-leading guidance and analysis for how to keep your business secure.\",\"publisher\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.esecurityplanet.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#organization\",\"name\":\"eSecurityPlanet\",\"url\":\"https:\/\/www.esecurityplanet.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png\",\"width\":1134,\"height\":375,\"caption\":\"eSecurityPlanet\"},\"image\":{\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/eSecurityPlanet\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/62368dee45ce8f1ffc35abf9f8cc854e\",\"name\":\"Jeff Burt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/Jeff-Burt-photo-150x150.jpg\",\"contentUrl\":\"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/Jeff-Burt-photo-150x150.jpg\",\"caption\":\"Jeff Burt\"},\"description\":\"Jeffrey Burt has been a journalist for more than three decades, the last 20-plus years covering technology. During more than 16 years with eWEEK, he covered everything from data center infrastructure and collaboration technology to AI, cloud, quantum computing and cybersecurity. A freelance journalist since 2017, his articles have appeared on such sites as eWEEK, eSecurity Planet, Enterprise Networking Planet, Enterprise Storage Forum, The Next Platform, ITPro Today, Channel Futures, Channelnomics, SecurityNow, and Data Breach Today.\",\"url\":\"https:\/\/www.esecurityplanet.com\/author\/jburt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Apple Patches Vulnerabilities in iOS Exploited by Spyware | eSecurity Planet","description":"NSO Group's Pegasus spyware continues to target Apple devices, and privacy and human rights advocates grow increasingly concerned.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/","og_locale":"en_US","og_type":"article","og_title":"Apple Patches Vulnerabilities in iOS Exploited by Spyware | eSecurity Planet","og_description":"NSO Group's Pegasus spyware continues to target Apple devices, and privacy and human rights advocates grow increasingly concerned.","og_url":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/","og_site_name":"eSecurity Planet","article_published_time":"2021-09-15T00:18:45+00:00","og_image":[{"width":1200,"height":626,"url":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg","type":"image\/jpeg"}],"author":"Jeff Burt","twitter_card":"summary_large_image","twitter_creator":"@eSecurityPlanet","twitter_site":"@eSecurityPlanet","twitter_misc":{"Written by":"Jeff Burt","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#article","isPartOf":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/"},"author":{"name":"Jeff Burt","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/62368dee45ce8f1ffc35abf9f8cc854e"},"headline":"Apple Patches Vulnerabilities in iOS Exploited by Spyware","datePublished":"2021-09-15T00:18:45+00:00","dateModified":"2021-09-15T00:18:45+00:00","mainEntityOfPage":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/"},"wordCount":1079,"publisher":{"@id":"https:\/\/www.esecurityplanet.com\/#organization"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg","keywords":["cyber threats","Data privacy","spyware"],"articleSection":["Compliance","Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/","url":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/","name":"Apple Patches Vulnerabilities in iOS Exploited by Spyware | eSecurity Planet","isPartOf":{"@id":"https:\/\/www.esecurityplanet.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage"},"thumbnailUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg","datePublished":"2021-09-15T00:18:45+00:00","dateModified":"2021-09-15T00:18:45+00:00","description":"NSO Group's Pegasus spyware continues to target Apple devices, and privacy and human rights advocates grow increasingly concerned.","breadcrumb":{"@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#primaryimage","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/spyware-e1626895488701.jpg","width":1200,"height":626,"caption":"spyware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.esecurityplanet.com\/threats\/apple-patches-ios-spyware-vulnerabilities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.esecurityplanet.com\/"},{"@type":"ListItem","position":2,"name":"Apple Patches Vulnerabilities in iOS Exploited by Spyware"}]},{"@type":"WebSite","@id":"https:\/\/www.esecurityplanet.com\/#website","url":"https:\/\/www.esecurityplanet.com\/","name":"eSecurity Planet","description":"Industry-leading guidance and analysis for how to keep your business secure.","publisher":{"@id":"https:\/\/www.esecurityplanet.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.esecurityplanet.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.esecurityplanet.com\/#organization","name":"eSecurityPlanet","url":"https:\/\/www.esecurityplanet.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2020\/10\/eSecurity_logo_MainLogo.png","width":1134,"height":375,"caption":"eSecurityPlanet"},"image":{"@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/eSecurityPlanet"]},{"@type":"Person","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/62368dee45ce8f1ffc35abf9f8cc854e","name":"Jeff Burt","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esecurityplanet.com\/#\/schema\/person\/image\/","url":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/Jeff-Burt-photo-150x150.jpg","contentUrl":"https:\/\/assets.esecurityplanet.com\/uploads\/2021\/07\/Jeff-Burt-photo-150x150.jpg","caption":"Jeff Burt"},"description":"Jeffrey Burt has been a journalist for more than three decades, the last 20-plus years covering technology. During more than 16 years with eWEEK, he covered everything from data center infrastructure and collaboration technology to AI, cloud, quantum computing and cybersecurity. A freelance journalist since 2017, his articles have appeared on such sites as eWEEK, eSecurity Planet, Enterprise Networking Planet, Enterprise Storage Forum, The Next Platform, ITPro Today, Channel Futures, Channelnomics, SecurityNow, and Data Breach Today.","url":"https:\/\/www.esecurityplanet.com\/author\/jburt\/"}]}},"_links":{"self":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts\/19250"}],"collection":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/users\/256"}],"replies":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/comments?post=19250"}],"version-history":[{"count":0,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/posts\/19250\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/media\/18859"}],"wp:attachment":[{"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/media?parent=19250"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/categories?post=19250"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/tags?post=19250"},{"taxonomy":"b2b_audience","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_audience?post=19250"},{"taxonomy":"b2b_industry","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_industry?post=19250"},{"taxonomy":"b2b_product","embeddable":true,"href":"https:\/\/www.esecurityplanet.com\/wp-json\/wp\/v2\/b2b_product?post=19250"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}