Hacked sites attacked thousands of iPhones every week for years using undiscovered exploits

The exploits were patched in February, but the details are new -- and serious.
 By 
Caitlin Welsh
 on 
Hacked sites attacked thousands of iPhones every week for years using undiscovered exploits
ICE has now spent more than $1 million on a tool that hacks into iPhones. Credit: Jaap Arriens / NurPhoto via Getty Images

In what's being touted as potentially one of the biggest attacks on iPhone users ever, Google has revealed that a collection of websites were hacked to deliver malware onto iPhones, with the iOS vulnerabilities involved going unchecked and undiscovered for years -- as well as subsequent attacks.

The hacks installed zero-interaction malware into unnamed sites that received thousands of visitors every week. Simply visiting the sites, without clicking or scrolling at all, could deliver a monitoring implant onto users' iPhones.

Google demonstrated that the implant could "steal private data like iMessages, photos and GPS location in real-time"; it also had access to users' keychains and password data, as well as database files containing plaintext of messages sent and received in messaging apps such as Google Hangouts, and even end-to-end encrypted apps including WhatsApp, iMessage, and Telegram.

The malware would be wiped if the iPhone was rebooted, but any sensitive information obtained during the infection could still leave the device, its user, and their online life vulnerable to attack.

While the choice of sites appeared designed to target certain communities, the attack was otherwise indiscriminate.

Google's security research initiative Project Zero posted a "very deep dive" detailing the exploits, which their Threat Analysis Group discovered and disclosed to Apple in Feb. 2019.

The team found five "separate, complete and unique" exploit chains using 14 vulnerabilities. Several were zero-day, meaning Apple was unaware of them at the time of Project Zero's discovery; Apple patched these within the seven-day deadline Google gave in iOS 12.1.4, the same Feb. 7 update that patched the infamous Group FaceTime vulnerability.

The exploits date back to iOS 10 and through updates of iOS 12.1.2, encompassing "almost every version" in that timeframe.

The number of Apple exploits discovered appears to have risen sharply over the past year. At the end of July, Project Zero revealed six zero-interaction security bugs that could be exploited through iMessage, only five of which Apple had managed to patch by the time the Google team revealed them. And in August, news broke of the SQLite vulnerability, as demonstrated at DEFCON 2019 using the iOS Contacts app, as well as the vulnerability to the Bluetooth-based "KNOB" attack that affected every iPhone and iPad.

Mashable has contacted Apple for comment.

Topics Cybersecurity

Mashable Image
Caitlin Welsh

Caitlin is Mashable's Australian Editor. She has written for The Guardian, Junkee, and any number of plucky little music and culture publications that were run on the smell of an oily rag and have since been flushed off the Internet like a dead goldfish by their new owners. She also worked at Choice, Australia's consumer advocacy non-profit and magazine, and as such has surprisingly strong opinions about whitegoods. She enjoys big dumb action movies, big clever action movies, cult Canadian comedies set in small towns, Carly Rae Jepsen, The Replacements, smoky mezcal, revenge bedtime procrastination, and being left the hell alone when she's reading.

Mashable Potato

Recommended For You

The European Commission got hacked for the second time this year
Europe flag

Seth Meyers shares theory on why Trump attacked Venezuela
Seth Meyers on 'Late Night with Seth Meyers.'

Apple responds to DarkSword spyware, the hacker tool targeting iPhones
Apple logo on iPhone


More in Tech
How to watch Chelsea vs. Port Vale online for free
Alejandro Garnacho of Chelsea reacts

How to watch 'Wuthering Heights' at home: Margot Robbie and Jacob Elordi's controversial romance now streaming
Margot Robbie and Jacob Elordi embracing in still from "Wuthering Heights"

How to watch New York Islanders vs. Philadelphia Flyers online for free
Matthew Schaefer of the New York Islanders warms up

How to watch Mexico vs. Belgium online for free
Israel Reyes of Mexico reacts

How to watch Brazil vs. Croatia online for free
Vinicius Junior #10 of Brazil leaves

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!