{"id":41874,"date":"2020-01-09T16:16:23","date_gmt":"2020-01-09T21:16:23","guid":{"rendered":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/?p=41874"},"modified":"2020-01-10T07:40:47","modified_gmt":"2020-01-10T12:40:47","slug":"google-imessage-clickless-ios-exploit-project-zero","status":"publish","type":"post","link":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/","title":{"rendered":"Google researcher beefs up iMessage security by demonstrating clickless exploit"},"content":{"rendered":"<p>Software exploits that don\u2019t require a victim to click a link to be compromised are an intriguing and growing area of research for white-hat hackers. So it is no surprise that Google\u2019s elite team of hackers, Project Zero, has dug into this stealthy mode of attack in recent months.<\/p>\n<p>On Thursday, <a href=\"https:\/\/twitter.com\/5aelo\">Samuel Gross<\/a> laid out how, armed with only a target\u2019s Apple ID, he could remotely compromise an iPhone within minutes to steal passwords, text messages and emails, and activate the camera and microphone.<\/p>\n<p>The attack, which exploited an iOS 12.4 <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-8641\">vulnerability<\/a>\u00a0for which <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/apple\/\">Apple<\/a> issued a patch last August, shows how \u201csmall design decisions can have significant security consequences,\u201d Gross\u00a0<a href=\"https:\/\/googleprojectzero.blogspot.com\/2020\/01\/remote-iphone-exploitation-part-1.html\">wrote<\/a> in a blog post.<\/p>\n<p>Gross poked holes in some conventional wisdom around security features used in the <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/iphone\/\">iPhone<\/a> operating system. A data-randomizing security feature known as ASLR meant to guard against exploits \u201cis not as strong in practice,\u201d he said. It could be broken, in part, through a side communications channel set up by the attacker to interact with the victim device, he said. By abusing the \u201creceipts\u201d feature that lets users know their iMessages have been delivered, Gross demonstrated remote code execution.<\/p>\n<p>Clickless exploits are anything but hypothetical. Last October, Facebook <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/facebook-nso-group-whatsapp-cfaa\/\">sued<\/a> software surveillance company <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/nso-group\/\">NSO Group<\/a>\u00a0for allegedly developing an exploit that infected about 1,400 mobile devices\u00a0that had\u00a0<a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/whatsapp\/\">WhatsApp<\/a>\u00a0installed. Users were reportedly infected if their phone was called \u2014\u00a0regardless of whether they answered the call. NSO Group denied involvement in the attack.<\/p>\n<p>Gross, who <a href=\"https:\/\/media.ccc.de\/v\/36c3-10497-messenger_hacking_remotely_compromising_an_iphone_through_imessage\">presented<\/a> his research at a hacking conference last month, said that he recommended new security measures to Apple based on his research.<\/p>\n<p>\u201cAs much code as possible should be put behind user interaction, in particular when receiving messages from unknown senders,\u201d he advised.<\/p>\n<p>Implementing all the recommendations, some of which <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/apple\/\">Apple<\/a> already has, \u201cshould make similar exploits significantly harder in the future,\u201d Gross argued.<\/p>\n<p>That, of course, is the whole point of <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/google-project-zero\/\">Project Zero<\/a>, which aims to take as many <a href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/tag\/zero-days\/\">zero-day exploits<\/a> \u2014\u00a0or those unknown to vendors \u2014 as possible\u00a0out of attackers\u2019 hands.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google&#8217;s Samuel Gross poked holes in some conventional wisdom around iOS. <\/p>\n","protected":false},"author":207,"featured_media":14248,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"disable_grayscale_images":true,"grayscale_contrast":0,"sponsored_content":false,"display_author_bio":true,"story_type":"","footnotes":""},"categories":[5],"tags":[234,105,278,1014,4947,4439,1159,740],"people":[],"special-report":[],"authors":[3237],"class_list":["post-41874","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-exploits","tag-apple","tag-google","tag-messaging-apps","tag-imessage","tag-zero-days","tag-ios","tag-google-project-zero","author-sean-lyngaas"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.8 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Google researcher beefs up iMessage security by demonstrating clickless exploit | CyberScoop<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google researcher beefs up iMessage security by demonstrating clickless exploit\" \/>\n<meta property=\"og:description\" content=\"Google&#039;s Samuel Gross poked holes in some conventional wisdom around iOS.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/\" \/>\n<meta property=\"og:site_name\" content=\"CyberScoop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cyberscoop\/\" \/>\n<meta property=\"article:published_time\" content=\"2020-01-09T21:16:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-01-10T12:40:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2017\/07\/iphone_dark_finger.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2048\" \/>\n\t<meta property=\"og:image:height\" content=\"1365\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sean Lyngaas\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@snlyngaas\" \/>\n<meta name=\"twitter:site\" content=\"@CyberScoopNews\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/\",\"name\":\"Google researcher beefs up iMessage security by demonstrating clickless exploit | CyberScoop\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2017\\\/07\\\/iphone_dark_finger.jpg\",\"datePublished\":\"2020-01-09T21:16:23+00:00\",\"dateModified\":\"2020-01-10T12:40:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/#primaryimage\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2017\\\/07\\\/iphone_dark_finger.jpg\",\"contentUrl\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2017\\\/07\\\/iphone_dark_finger.jpg\",\"width\":2048,\"height\":1365,\"caption\":\"(Flickr \\\/ Wiyre Media)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/google-imessage-clickless-ios-exploit-project-zero\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Google researcher beefs up iMessage security by demonstrating clickless exploit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#website\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/\",\"name\":\"CyberScoop\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#organization\",\"name\":\"CyberScoop\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/01\\\/CyberScoop-Black.png\",\"contentUrl\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2023\\\/01\\\/CyberScoop-Black.png\",\"width\":1545,\"height\":186,\"caption\":\"CyberScoop\"},\"image\":{\"@id\":\"https:\\\/\\\/scoopmedia-develop.go-vip.net\\\/cyberscoop\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/cyberscoop\\\/\",\"https:\\\/\\\/x.com\\\/CyberScoopNews\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/cyberscoop\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCDG2jjHiZ8r97MCVnsaAkXw\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Google researcher beefs up iMessage security by demonstrating clickless exploit | CyberScoop","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/","og_locale":"en_US","og_type":"article","og_title":"Google researcher beefs up iMessage security by demonstrating clickless exploit","og_description":"Google's Samuel Gross poked holes in some conventional wisdom around iOS.","og_url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/","og_site_name":"CyberScoop","article_publisher":"https:\/\/www.facebook.com\/cyberscoop\/","article_published_time":"2020-01-09T21:16:23+00:00","article_modified_time":"2020-01-10T12:40:47+00:00","og_image":[{"width":2048,"height":1365,"url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2017\/07\/iphone_dark_finger.jpg","type":"image\/jpeg"}],"author":"Sean Lyngaas","twitter_card":"summary_large_image","twitter_creator":"@snlyngaas","twitter_site":"@CyberScoopNews","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/","name":"Google researcher beefs up iMessage security by demonstrating clickless exploit | CyberScoop","isPartOf":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#website"},"primaryImageOfPage":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/#primaryimage"},"image":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/#primaryimage"},"thumbnailUrl":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2017\/07\/iphone_dark_finger.jpg","datePublished":"2020-01-09T21:16:23+00:00","dateModified":"2020-01-10T12:40:47+00:00","breadcrumb":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/#primaryimage","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2017\/07\/iphone_dark_finger.jpg","contentUrl":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2017\/07\/iphone_dark_finger.jpg","width":2048,"height":1365,"caption":"(Flickr \/ Wiyre Media)"},{"@type":"BreadcrumbList","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/google-imessage-clickless-ios-exploit-project-zero\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/"},{"@type":"ListItem","position":2,"name":"Google researcher beefs up iMessage security by demonstrating clickless exploit"}]},{"@type":"WebSite","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#website","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/","name":"CyberScoop","description":"","publisher":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#organization","name":"CyberScoop","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#\/schema\/logo\/image\/","url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/01\/CyberScoop-Black.png","contentUrl":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2023\/01\/CyberScoop-Black.png","width":1545,"height":186,"caption":"CyberScoop"},"image":{"@id":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/cyberscoop\/","https:\/\/x.com\/CyberScoopNews","https:\/\/www.linkedin.com\/company\/cyberscoop\/","https:\/\/www.youtube.com\/channel\/UCDG2jjHiZ8r97MCVnsaAkXw"]}]}},"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"CyberScoop","distributor_original_site_url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop","push-errors":false,"jetpack_featured_media_url":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-content\/uploads\/sites\/3\/2017\/07\/iphone_dark_finger.jpg","_links":{"self":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts\/41874","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/users\/207"}],"replies":[{"embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/comments?post=41874"}],"version-history":[{"count":8,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts\/41874\/revisions"}],"predecessor-version":[{"id":41884,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/posts\/41874\/revisions\/41884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/media\/14248"}],"wp:attachment":[{"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/media?parent=41874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/categories?post=41874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/tags?post=41874"},{"taxonomy":"people","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/people?post=41874"},{"taxonomy":"special-report","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/special-report?post=41874"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/scoopmedia-develop.go-vip.net\/cyberscoop\/wp-json\/wp\/v2\/authors?post=41874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}