The Citizen Lab at the University of Toronto Munk School in Ontario, Canada recently identified two new zero-click vulnerabilities being actively exploited in iOS systems by the NSO Group.
NSO is an Israeli cyber-intelligence firm which deals with government clients, however its trademark malware – Pegasus – has been used in the past to target political dissidents and journalists.
The exploit requires no input from the target victim, which is why it is being called a zero-click infection, and can take advantage of unpatched vulnerabilities in both iOS and Android devices.
Once loaded, Pegasus can monitor calls, messages, and photos from a victim’s phone. It can even go as far as to turn on the device’s front and rear camera, microphone and track the location of the user.
Recommended reading
- Five Things You Need to Know About iOS 16
- Google’s Project Zero Uncovers Major iPhone Security Flaw
- Apple Updating iPhone to Avoid Law Enforcement Access
This particular exploit is being referred to as BLASTPASS, and it leverages weaknesses in Image I/O, which allows applications to read and write file formats, and the Apple Wallet application software.
The exploit targets Apple devices running iOS 16.6 or older. The new emergency update is called iOS 16.6.1 for iPhones. To see what iOS is installed, open the Settings application, navigate to “General” and find the “About” section. The iOS version will be visible there, and if it is 16.6 or earlier, navigate back to “General” and go to “Software Update” to install the latest iOS.
According to the Canadian researchers, the exploit will send attachments containing malicious images in an iMessage to the victim, and will compromise the victim’s device without any interaction on their part.
Apple has said they are “aware of a report that this issue may have been actively exploited.” The team at the Citizen Lab say they expect to publish a more detailed discussion of the exploit chain in the future.
For users who feel they have been targeted by malware, The Citizen Lab recommends enabling Lockdown Mode, which is an extreme protection measure against spyware. While this mode may disrupt the function of other apps, it will reduce the attack surface of your device.
The updated versions on other Apple operating systems are: iPadOS 16.6.1, macOS Ventura 13.5.2, watchOS 9.6.2.





