New Flaw in Apple Devices Led to Spyware Infection, Researchers Say

Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
TT
20

New Flaw in Apple Devices Led to Spyware Infection, Researchers Say

Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)

Researchers at digital watchdog group Citizen Lab said on Thursday they found spyware they linked to Israeli firm NSO that exploited a newly discovered flaw in Apple devices.

While inspecting the Apple device of an employee of a Washington-based civil society group last week, Citizen Lab said it found the flaw had been used to infect the device with NSO's Pegasus spyware, it said in a statement.

"We attribute the exploit to NSO Group's Pegasus spyware with high confidence, based on forensics we have from the target device," said Bill Marczak, senior researcher at Citizen Lab, which is based at the University of Toronto's Munk School of Global Affairs and Public Policy.

He said the attacker likely made a mistake during the installation which is how Citizen Lab found the spyware.

Citizen Lab said Apple confirmed to them that using the high security feature "Lockdown Mode" available on Apple devices blocks this particular attack.

"This shows that civil society is once again serving as the early warning system about really sophisticated attacks," said John Scott-Railton, senior researcher at Citizen Lab.

Citizen Lab did not provide further details on the affected individual or the organization.

The flaw allowed compromise of iPhones running the latest version of iOS (16.6) without any interaction from the victim, the digital watchdog said. The new update fixes this vulnerability.

Apple issued new updates on its devices after investigating the flaws reported by Citizen Lab. An Apple spokesperson said it had no further comment, while Citizen Lab urged consumers to update their devices.

NSO said in a statement, "We are unable to respond to any allegations that do not include any supporting research."

The Israeli firm has been blacklisted by the US government since 2021 for alleged abuses, including surveillance of government officials and journalists.



DeepSeek Faces Expulsion from App Stores in Germany

FILE - The smartphone apps DeepSeek page is seen on a smartphone screen in Beijing, Tuesday, Jan. 28, 2025. (AP Photo/Andy Wong, File)
FILE - The smartphone apps DeepSeek page is seen on a smartphone screen in Beijing, Tuesday, Jan. 28, 2025. (AP Photo/Andy Wong, File)
TT
20

DeepSeek Faces Expulsion from App Stores in Germany

FILE - The smartphone apps DeepSeek page is seen on a smartphone screen in Beijing, Tuesday, Jan. 28, 2025. (AP Photo/Andy Wong, File)
FILE - The smartphone apps DeepSeek page is seen on a smartphone screen in Beijing, Tuesday, Jan. 28, 2025. (AP Photo/Andy Wong, File)

Germany has taken steps towards blocking Chinese AI startup DeepSeek from the Apple and Google app stores due to concerns about data protection, according to a data protection authority commissioner in a statement on Friday.

DeepSeek has been reported to the two US tech giants as illegal content, said commissioner Meike Kamp, and the companies must now review the concerns and decide whether to block the app in Germany, Reuters reported.

"DeepSeek has not been able to provide my agency with convincing evidence that German users' data is protected in China to a level equivalent to that in the European Union," she said.

"Chinese authorities have far-reaching access rights to personal data within the sphere of influence of Chinese companies," she added.

The move comes after Reuters exclusively reported this week that DeepSeek is aiding China's military and intelligence operations.

DeepSeek, which shook the technology world in January with claims that it had developed an AI model that rivaled those from US firms such as ChatGPT creator OpenAI at much lower cost, says it stores numerous personal data, such as requests to the AI or uploaded files, on computers in China.