BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild

Mwalimu@baraza.africa to Technology@lemmy.world – 93 points –
BLASTPASS: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild - The Citizen Lab
citizenlab.ca

We refer to the exploit chain as BLASTPASS. The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim.

8

The fine folks at CitizenLab are doing such important work. I just want to call out what a net-benefit they are for us all. I can't count how many times I see or hear their name in sec updates, sec podcasts, news stories, etc. Thank you to CitizenLab!

I hear only good stuff from them. I think they were featured in the last episode of darkness diaries too.

Must be what the 16.6.1 update was for last night

Yes. The linked article points to Apple’s release notes.

CVE-2023-41064: The Citizen Lab at The University of Torontoʼs Munk School

"iPhones don't have malware"

Who claims that anymore? Ever since covid there's been tons of zero days updates. The only security benefit is not having extremely delayed updates like most android devices.

Lots of people think iphones are secure.