Can the CIA hack your iPhone? What you need to know about the WikiLeaks dump.

"Dark Matter" is freaking people out.
 By 
Karissa Bell
 on 
Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

The CIA has put quite a bit effort into figuring out ways to hack Apple devices.That's the takeaway from the latest batch of documents dumped by WikiLeaks.

The so-called "Dark Matter"documents, published Thursday, detail methods allegedly used by the CIA to infect MacBooks and some older iPhones with malware that allowed the agency to remotely spy on device owners.

As usual, WikiLeaks released a fairly alarming-sounding statement accompanying the documents. But before you freak out about the security of your own Apple products, it's important to understand exactly what they say.

Physical access is everything

It's important to note that, much like the earlier Vault 7 dump that detailed exploits used to "bypass" encryption used by chat apps like WhatsApp and Signal, the new methods described in the latest documents also require physical access to the device.

The documents make completely clear the fact that CIA operatives would need physical access to a device before they can carry out any of the exploits described.

So what was that about an iPhone?

First, the good news. The only iPhone specifically named in the documents is one that is pretty much completely dead: the iPhone 3G (running iOS 2.1, no less). Apple also confirmed Thursday the only iPhone affected was the 3G and that the vulnerability was fixed as of the release of the iPhone 3GS.

Still, the exploit detailed in a document called NightSkies, dated to 2008, involved "a beacon/loader/implant tool" that "operates in the background providing upload, download and execution capability on the device."

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

The setup process was somewhat complex (again, it required physical access to the phone), but once there, it could have been used to access an astonishingly vast amount of data from a "target's" iPhone.

The document contains instructions for downloading call logs, text messages, contacts lists, mail and maps files, browser history, YouTube video cache (YouTube was one of the only third-party apps to come pre-installed on early iPhones), voicemails, calendar data, photos and even "user-specific" keyboard data. In other words: very nearly everything you could possibly hope to get off an iPhone using the app's that came pre-installed at the time.

What about the MacBooks?

It all started with a dongle. Seriously.

A project called Sonic Screwdriver (yes, we already know the CIA is full of Doctor Who fans) detailed how a thunderbolt-to-ethernet adapter could be modified with a bit of malicious code designed to infect a laptop's firmware.

Original image replaced with Mashable logo
Original image has been replaced. Credit: Mashable

By infecting the firmware, this allowed the code to "persist" in the device even if the hard drive was wiped or the operating system is completely re-installed. As Motherboard's Lorenzo Franceschi-Bicchierai points out, it was actually a fairly clever move by the CIA as a similar method was later uncovered by security researchers two years later in 2014.

According to the documents, the CIA tested this method with MacBook Pros and MacBook Airs from late 2011 to mid 2012. (In a statement, Apple said this particular exploit had been fixed in every MacBook made after 2013.)

But, again, before you go chucking your own ethernet adapter in the garbage, remember that this only worked with adapters that had been specially modified with the malicious code to begin with.

Topics Apple iPhone

Mashable Image
Karissa Bell

Karissa was Mashable's Senior Tech Reporter, and is based in San Francisco. She covers social media platforms, Silicon Valley, and the many ways technology is changing our lives. Her work has also appeared in Wired, Macworld, Popular Mechanics, and The Wirecutter. In her free time, she enjoys snowboarding and watching too many cat videos on Instagram. Follow her on Twitter @karissabe.

Mashable Potato

Recommended For You
Comparing iPhone 17e vs. iPhone 17: Is the new $599 phone good enough?
iphone 17 and 17e on blue background

Score a free Apple iPhone 17e from T-Mobile — how to claim your free iPhone this weekend
the apple iphone 17e in several colorways in a row, overlapping each other in front of a green background

iPhone Fold leaks, rumors, and renders: Everything we know
a hypothetical render of the iPhone Fold on a stylized mashable background

You can get a new Apple iPhone 13 for under $100 — here's the details
Apple iPhone 13 with purple and blue background

What are 'claws'? The next AI term you’ll need to know.
OpenClaw logo on laptop screen

More in Tech
Age-verification is hurting sex educators and sex workers, studies suggest
pixelated image of two men embracing with age gate in front of it

The Guess Who? Pokémon Edition game just dropped. Here's where to buy it before it sells out.
the new Pokemon guess who game on a purple and pink background


Amazon has slashed $22 off the Lego Star Wars C-3PO buildable droid figure — buy now for under $120
lego star wars c-3po buildable droid figure against a pink and purple patterned background

Lego has dropped a World Cup collection featuring Messi and Ronaldo: Here’s where to pre-order now
New Lego Lionel Messi figure

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

What's new to streaming this week? (April 3, 2026)
A composite of images from film and TV streaming this week.

NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

You can track Artemis II in real time as Orion flies to the moon
Victor Glover and Reid Wiseman piloting the Orion spacecraft
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!