Article 5T6QE Researchers Call NSO Zero-Click iPhone Exploit "Incredible and Terrifying"

Researchers Call NSO Zero-Click iPhone Exploit "Incredible and Terrifying"

by
janrinok
from SoylentNews on (#5T6QE)

upstart writes:

Researchers call NSO zero-click iPhone exploit 'incredible and terrifying':

Google researchers have described NSO Group's zero-click exploit used to hack Apple devices as "incredible and terrifying," Wired has reported. Project Zero researchers called it "one of the most technically sophisticated exploits we've ever seen" that's on par with attacks from elite nation-state spies.

The Project Zero team said it obtained one of NSO's Pegasus exploits from Citizen Lab, which managed to capture it via a targeted Saudi activist. It also worked with Apple's Security Engineering and Architecture (SEAR) group on the technical analysis.

NSO's original exploit required the user to click on a link, but the latest, most sophisticated exploits require no click at all. Called ForcedEntry, it takes advantage of the way iMessage interprets files like GIFs to open a malicious PDF file with no action required from the victim. It does so by using old code from the 1990s used to process text in scanner images.

Also at: Google Warns That NSO Hacking Is On Par With Elite Nation-State Spies:

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments