Modern Australian
The Times

Apple iPhones could have been hacked for years – here's what to do about it

  • Written by Leslie Sikos, Lecturer, Edith Cowan University

For many years, the Apple iPhone has been considered one of the most secure smart phones available. But despite this reputation, security issues that might affect millions of users came to light last week, when researchers at Google revealed they had discovered websites that can infect iPhones, iPads, and iPods with dangerous software.

Simply visiting one of these websites is enough to infect your device with malicious software, allowing a high level of access to the device. Worryingly, it seems these vulnerabilities have been “in the wild” (that is, actively used by cyber-criminals) for around two years.

As there is no visible sign of infection on the device, it is likely users are completely unaware of the risks they’re facing.

Read more: Don't click that link! How criminals access your digital devices and what happens when they do

The vulnerabilities being exploited are present on devices running recent (but not the most recent) versions of Apple’s iOS operating system — specifically, iOS 10 through to early versions of iOS 12. Every device running the vulnerable versions of iOS is a potential target for these websites.

Devices are infected via several methods, using 14 different security flaws — an unusual number of ways to compromise a device. Worse is that seven of the flaws involve Safari, the default web browser for many of these devices (and web browsing is a common activity for many users).

It’s not all bad news though. After Google reported the issues to Apple earlier this year, the vulnerabilities were promptly patched with the latest release of iOS (12.4.1).

Any user updating their device to the latest version of iOS should be protected against this attack. The easiest way to do it is to go to Settings > General > Software Update on your phone and then follow the prompts.

What happens when you visit an infected site?

As soon you open the web page, malicious software is installed on the device. This software has the potential to access location data and information stored by various apps (such as iMessage, WhatsApp, and Google Hangouts).

This information can be transmitted to a remote location and potentially misused by an attacker. The information extracted can include messages that are otherwise protected when sent and received by the user, removing the protection offered through encryption. Hackers can also potentially access private files stored on the device, including photos, emails, contact lists, and sensitive information such as WiFi passwords.

All of this data has value and can be sold on the Internet to other cyber-criminals.

According to antivirus firm Malwarebytes, the malicious software is removed when the infected device is restarted. While this limits the amount of time that the device is compromised, the user risks being reinfected the next time they visit the same website (if still using a vulnerable version of iOS).

The list of websites involved has not yet been made publicly available, so users have no means to protect themselves other than by updating their device’s operating system. But we do know the number of visitors to these sites are estimated in the thousands per week.

Are Apple devices no longer secure?

High-profile attacks on these devices might dispel the myth that Apple devices are not susceptible to serious security breaches. However, Apple does have a bug-bounty program that offers a US$1 million reward to users who report problems that help to identify security flaws.

But considering the impact of this incident, it’s obvious someone out there is making considerable efforts to target Apple devices. While the tech giant regularly updates its software, there have been recent incidents in which previously fixed security flaws were reintroduced. This highlights the complexity of these devices and the challenge of maintaining a secure platform.

Read more: Everyone falls for fake emails: lessons from cybersecurity summer school

The most important lesson for Apple’s millions of users is to ensure you keep up to date with the latest patches and fixes. Simply installing the latest iOS update is sufficient to remove the threats caused by this vulnerability.

If you’re concerned your details may have been stolen, changing passwords and checking your credit card and bank account statements are also important steps to take.

Authors: Leslie Sikos, Lecturer, Edith Cowan University

Read more http://theconversation.com/apple-iphones-could-have-been-hacked-for-years-heres-what-to-do-about-it-122860

Your Baby's First Year: A Local Guide to Feeding, Sleep, and When to Get Extra Support

Ask ten parents in a Brisbane mothers' group how their baby is feeding or sleeping, and expect ten different answers.  Someone's baby sleeps throu...

Kitchen and Laundry Makeover Ideas That Don't Require a Full Renovation

Full kitchen renos are expensive — and most people don't actually need one.  They need the kitchen to stop looking like it's stuck in 2009, or t...

How Technology Is Reshaping the Modern Australian Commercial Kitchen

The commercial kitchen has always been shaped by technology. Refrigeration changed how ingredients could be stored, modern ventilation transformed k...

The Number on a Roller Blind Fabric That Nobody Explains

Somewhere in the fabric book, next to the colour name, there is a percentage. Three per cent. Five per cent. Ten per cent. Nobody explains it, most c...

What’s Trending in Men’s Jewellery This Father’s Day!

Finding a Father’s Day gift that feels personal, stylish and genuinely wearable is not always easy. While socks and novelty mugs have traditionall...

Road Signs: Understanding Their Role in Clear and Effective Signage

Effective signage and display hardware can help businesses communicate information, promote products and organise customer or visitor movement. Road...

Bottle Label Printing: Key Factors to Consider Before Your Next Packaging Run

Effective packaging begins with understanding the product, bottle material, artwork and production requirements when planning bottle label printing. H...

Planning a Long-Distance Move With Interstate Movers Melbourne

Moving between states involves more planning than a typical local relocation. Along with packing and transporting household belongings, you need to...

Understanding the Role of an I/O Controller in Industrial Automation

Modern industrial systems depend on accurate communication between sensors, machines and control systems. An I/O controller can help manage this commu...

How the Right Mining Hose Supports Demanding Operations

Mining environments place considerable demands on equipment used for material transfer, water management and processing. Hoses operating in these co...

Simple Ideas for Making Social Gatherings More Memorable

We have all been to those parties where everyone just stands around the kitchen island, staring at their phones, waiting for someone else to make a mo...

Outdoor Wall Lights: Improving Exterior Lighting Around Your Home

Lighting can influence how a room looks, feels and functions, so the right fitting should be selected according to both appearance and practical req...

Commercial Office Cleaning: Combining Routine Office Cleaning With Melbourne Service

Keeping a workplace clean requires a service that can accommodate everyday tasks as well as the particular needs of the business. Professional comme...

Caravan Sales in Queensland: How to Find the Right Caravan for Sale QLD

Caravan ownership is about more than having somewhere to sleep while travelling. For many Queenslanders, it is one of the best ways to explore regio...

What Sir Walter Buffalo Turf Actually Costs in 2026 (And Why Quotes Vary So Much)

Two quotes landed on a Hills District homeowner's kitchen table last spring for the exact same 80-square-metre backyard. One said $12 a metre. The o...

Nearly 1,300 NSW Hospital Beds Are Occupied By People Who Are Ready To Go Home

1,276 people in NSW hospitals have been medically cleared for discharge but remain in hospital because they're still waiting for NDIS or aged care sup...

National Survey Launched to Measure Operational Impacts of Federal NDIS Policy Reforms

The effects of recent NDIS reforms are beginning to move beyond policy papers and into day to day service delivery. A new national survey is asking ...

Beyond the Nappy Cake: Baby Shower Gifts That Get Used

What new Australian parents unwrap, keep, and quietly thank you for months later. Six weeks after my daughter was born, I did an audit of the baby sh...