New Flaw in Apple Devices Led to Spyware Infection, Researchers Say

Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
TT
20

New Flaw in Apple Devices Led to Spyware Infection, Researchers Say

Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)
Apple iPhone 14 phones sit on display at an Apple Store at The Grove in Los Angeles, Sept. 16, 2022. (AP)

Researchers at digital watchdog group Citizen Lab said on Thursday they found spyware they linked to Israeli firm NSO that exploited a newly discovered flaw in Apple devices.

While inspecting the Apple device of an employee of a Washington-based civil society group last week, Citizen Lab said it found the flaw had been used to infect the device with NSO's Pegasus spyware, it said in a statement.

"We attribute the exploit to NSO Group's Pegasus spyware with high confidence, based on forensics we have from the target device," said Bill Marczak, senior researcher at Citizen Lab, which is based at the University of Toronto's Munk School of Global Affairs and Public Policy.

He said the attacker likely made a mistake during the installation which is how Citizen Lab found the spyware.

Citizen Lab said Apple confirmed to them that using the high security feature "Lockdown Mode" available on Apple devices blocks this particular attack.

"This shows that civil society is once again serving as the early warning system about really sophisticated attacks," said John Scott-Railton, senior researcher at Citizen Lab.

Citizen Lab did not provide further details on the affected individual or the organization.

The flaw allowed compromise of iPhones running the latest version of iOS (16.6) without any interaction from the victim, the digital watchdog said. The new update fixes this vulnerability.

Apple issued new updates on its devices after investigating the flaws reported by Citizen Lab. An Apple spokesperson said it had no further comment, while Citizen Lab urged consumers to update their devices.

NSO said in a statement, "We are unable to respond to any allegations that do not include any supporting research."

The Israeli firm has been blacklisted by the US government since 2021 for alleged abuses, including surveillance of government officials and journalists.



US Auto Safety Agency Reviewing Tesla Answers on Robotaxi Deployment Plans

FILE PHOTO: The logo of Tesla is seen on a store in Paris, France, October 30, 2020. REUTERS/Charles Platiau/File Photo
FILE PHOTO: The logo of Tesla is seen on a store in Paris, France, October 30, 2020. REUTERS/Charles Platiau/File Photo
TT
20

US Auto Safety Agency Reviewing Tesla Answers on Robotaxi Deployment Plans

FILE PHOTO: The logo of Tesla is seen on a store in Paris, France, October 30, 2020. REUTERS/Charles Platiau/File Photo
FILE PHOTO: The logo of Tesla is seen on a store in Paris, France, October 30, 2020. REUTERS/Charles Platiau/File Photo

US highway safety regulators are reviewing answers Tesla gave in response to the agency's questions about the safety of its self-driving robotaxi in poor weather, the agency said on Friday, ahead of plans to deploy the vehicles as soon as this weekend.

Tesla has sent invitations to a small group of people to join in a limited test of its robotaxi service in Austin, Texas, which is tentatively set to start on Sunday, according to posts and email screenshots on social media.

In a letter last month, NHTSA asked Tesla to answer detailed questions by June 19 on its plans to launch paid robotaxi service in Austin, to assess how the electric vehicle maker's cars with full self-driving technology will perform in poor weather, Reuters said.

The agency said it has received Tesla's response "and is in the process of reviewing it. Once our review has been completed the public file will be updated."

Tesla did not immediately respond to a request for comment.

The invitations said a Tesla employee will accompany riders in the front passenger seat, the posts showed. NHTSA asked Tesla if vehicles "will be supervised or otherwise monitored by Tesla in real time."

NHTSA has been investigating Tesla full self-driving collisions in reduced roadway visibility conditions since October. The probe covers 2.4 million Tesla vehicles equipped with full self-driving technology after four reported collisions, including a 2023 fatal crash.

The agency said in May it was seeking additional information about Tesla's development of robotaxis "to assess the ability of Tesla's system to react appropriately to reduced roadway visibility conditions" as well details on robotaxi deployment plans and the technology being used.

NHTSA said in May it wants to know how many vehicles will be used as robotaxis and the expected timetable for availability of robotaxi technology for vehicles controlled by people other than Tesla.

NHTSA's letter asked Tesla to describe how it intends to ensure the safety of robotaxi operations in reduced roadway visibility conditions such as sun glare, fog, airborne dust, rain, or snow. It also wants to know what happens if poor visibility is encountered during a ride.

Tesla CEO Elon Musk has said he will focus on safety in the trial, with humans remotely monitoring the vehicles.