Skip to content
General

New iMessage exploit allows hackers to hijack your iPhone by simply sending you a message

By Rajiv Menon
2 min read
Imessage
Imessage
In this article (5)

A new, “interaction-less” bug in iMessage was recently discovered that could allow hackers to gain access to your iPhone. The exploit being interaction-less means that you don’t need to do anything—download any files or click any suspicious links—to get your device compromised. What’s even worse, you don’t even need to open the iMessage app for the exploit to work.

At the Black Hat security conference in Las Vegas this week, Google Project Zero researcher Natalie Silvanovich showed off a number of these so-called interaction-less bugs in iMessage that could be used to gain remote access to an iPhone. Apple has already patched five of them, but there are a handful that are yet to receive the company’s attention.

Following the recently uncovered vulnerabilities in WhatsApp, Silvanovich and her colleague Samuel Groß started investigating for similar exploits in SMS, MMS, and voicemail but found none. Then, they shifted their attention to iMessage and started reverse-engineering the app, which lead to some worrisome discoveries.

According to the researchers, the vulnerabilities that they uncovered in iMessage are likely a result of the complex (and ever-expanding) nature of the app. Apple’s messaging client not only allows users to send each other files, voice messages, photos, and Animojis, but also has many integrations with third-party apps, like OpenTable and Airbnb. This makes securing every potential backdoor increasingly difficult, though the researchers claim that Apple is actually doing a good job.

Silvanovich says that iOS has many security checks in place, but the bug she and Groß discovered takes advantage of the underlying logic of the operating system, which makes it possible to bypass the security net. A potential attacker could send a targeted iMessage with specific content in it that Apple’s servers would interpret in a certain way and send the target a message that would then automatically trigger the exploit, granting the attacker access to the phone.

Interaction-less bugs are highly sought after in the hacking community, as they don’t require the target to do anything. The iMessage vulnerabilities discovered by the Google Project Zero members could fetch prices in the vicinity of “millions or even tens of millions” on the exploit market.

Questions & Answers

Q.

What is meant by an 'interaction-less' bug in iMessage?

A.

An 'interaction-less' bug means that a user does not need to download files, click suspicious links, or even open the iMessage app for their device to be compromised. The exploit works without any action from the target.

Q.

Which security experts discovered these iMessage vulnerabilities?

A.

Google Project Zero researchers Natalie Silvanovich and her colleague Samuel Groß uncovered these vulnerabilities. They shifted their focus to iMessage after investigating other messaging services for similar exploits.

Q.

Why do the researchers believe iMessage has these security vulnerabilities?

A.

The researchers suggest the vulnerabilities are likely due to the complex and ever-expanding nature of the iMessage app. Its many features and third-party integrations make securing every potential backdoor difficult.

Q.

Has Apple addressed all the iMessage bugs found by the researchers?

A.

Apple has already patched five of the interaction-less bugs discovered. However, a handful of vulnerabilities are yet to receive the company’s attention and remain unpatched.

Reader pulse

How concerned are you about this iMessage vulnerability?

23,221 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready