New Flaw in Apple Devices Led to Spyware Infection, Researchers Say

Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
TT
20

New Flaw in Apple Devices Led to Spyware Infection, Researchers Say

Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)

Researchers at digital watchdog group Citizen Lab said on Thursday they found spyware they linked to Israeli firm NSO that exploited a newly discovered flaw in Apple devices.

While inspecting the Apple device of an employee of a Washington-based civil society group last week, Citizen Lab said it found the flaw had been used to infect the device with NSO's Pegasus spyware, it said in a statement.

"We attribute the exploit to NSO Group's Pegasus spyware with high confidence, based on forensics we have from the target device," said Bill Marczak, senior researcher at Citizen Lab, which is based at the University of Toronto's Munk School of Global Affairs and Public Policy.

He said the attacker likely made a mistake during the installation which is how Citizen Lab found the spyware.

Citizen Lab said Apple confirmed to them that using the high security feature "Lockdown Mode" available on Apple devices blocks this particular attack.

"This shows that civil society is once again serving as the early warning system about really sophisticated attacks," said John Scott-Railton, senior researcher at Citizen Lab.

Citizen Lab did not provide further details on the affected individual or the organization.

The flaw allowed compromise of iPhones running the latest version of iOS (16.6) without any interaction from the victim, the digital watchdog said. The new update fixes this vulnerability.

Apple issued new updates on its devices after investigating the flaws reported by Citizen Lab. An Apple spokesperson said it had no further comment, while Citizen Lab urged consumers to update their devices.

NSO said in a statement, "We are unable to respond to any allegations that do not include any supporting research."

The Israeli firm has been blacklisted by the US government since 2021 for alleged abuses, including surveillance of government officials and journalists.



US May Target Samsung, Hynix, TSMC Operations in China

A man walks past the logo of Samsung Electronics displayed outside the company's Seocho building in Seoul on April 30, 2025. (Photo by Jung Yeon-je / AFP)
A man walks past the logo of Samsung Electronics displayed outside the company's Seocho building in Seoul on April 30, 2025. (Photo by Jung Yeon-je / AFP)
TT
20

US May Target Samsung, Hynix, TSMC Operations in China

A man walks past the logo of Samsung Electronics displayed outside the company's Seocho building in Seoul on April 30, 2025. (Photo by Jung Yeon-je / AFP)
A man walks past the logo of Samsung Electronics displayed outside the company's Seocho building in Seoul on April 30, 2025. (Photo by Jung Yeon-je / AFP)

The US Department of Commerce is considering revoking authorizations granted in recent years to global chipmakers Samsung, SK Hynix and TSMC, making it more difficult for them to receive US goods and technology at their plants in China, according to people familiar with the matter.

The chances of the United States withdrawing the authorizations are unclear. But with such a move, it would be harder for foreign chipmakers to operate in China, where they produce semiconductors used in a wide range of industries, Reuters said.

A White House official said the United States was "just laying the groundwork" in case the truce reached between the two countries fell apart. But the official expressed confidence that the trade agreement would go forward and that rare earths would flow from China, as agreed.

"There is currently no intention of deploying this tactic," the official said. "It's another tool we want in our toolbox in case either this agreement falls through or any other catalyst throws a wrench in bilateral relations."

Shares of US chip equipment makers that supply plants in China fell when the Wall Street Journal first reported the news earlier on Friday. KLA Corp dropped 2.4%, Lam Research fell 1.9% and Applied Materials sank 2%. Shares of Micron, a major competitor to Samsung and SK Hynix in the memory chip sector, rose 1.5%.

A TSMC spokesman declined comment. Samsung and Hynix did not immediately respond to requests for comment. Lam Research, KLA and Applied Materials did not immediately respond, either.

In October 2022, after the United States placed sweeping restrictions on US chipmaking equipment to China, it gave foreign manufacturers like Samsung and Hynix letters authorizing them to receive goods.

In 2023 and 2024, the companies received what is known as Validated End User status in order to continue the trade.

A company with VEU status is able to receive designated goods from a US company without the supplier obtaining multiple export licenses to ship to them. VEU status enables entities to receive US-controlled products and technologies "more easily, quickly and reliably," as the Commerce Department website puts it.

The VEU authorizations come with conditions, a person familiar with the matter said, including prohibitions on certain equipment and reporting requirements.

“Chipmakers will still be able to operate in China," a Commerce Department spokesperson said in a statement when asked about the possible revocations. "The new enforcement mechanisms on chips mirror licensing requirements that apply to other semiconductor companies that export to China and ensure the United States has an equal and reciprocal process.”

Industry sources said that if it became more difficult for US semiconductor equipment companies to ship to foreign multinationals, it would only help domestic Chinese competitors.

"It’s a gift," one said.