Skip to main content
  1. Home
  2. Phones
  3. Apple
  4. Mobile
  5. News

Pegasus and BlastDoor are why you need to update your Apple devices immediately

Add as a preferred source on Google

The iPhone 13 may be ready to launch tomorrow, but Apple is working fast to patch a major vulnerability to its devices with a new update for iOS 14.8, iPad 14.8, and watchOS 7.6.2, none of which were given a beta test period first. While none contain major features as you might expect in advance of tomorrow’s “California Streaming” event, these are important security updates, as they contain fixes to two system vulnerabilities.

The potentially more serious one is Pegasus, which is an invasive spyware discovered by Israel’s NSO group. This “zero-click” exploit requires no input from a phone’s user to take effect, and was being used specifically against activists in Bahrain, including members of the Bahrain Centre for Human Rights. By defeating Apple’s BlastDoor security system, the ForcedEntry exploit was able to install the Pegasus spyware suite for purposes of surveillance.

Recommended Videos

According to the New York Times, the spyware is capable of infecting a wide range of Apple devices. Once infected, it can turn on your device’s camera and microphone, record messages, and access texts, emails, and calls, even ones that are encrypted.

Signal App
Signal

The second vulnerability allows attackers to get around BlastDoor, which was implemented in January in order to put a line of defense between the Messages app and the rest of iOS.

Messages have traditionally been the weakest link in iOS devices’ security, as Apple didn’t do a great job of sanitizing incoming data from other users; at its nadir, it was possible for a bad actor to take control of someone else’s iPhone by sending it a specific text message or photo. BlastDoor works by filtering out incoming bad code.

According to the official patch notes, the new updates affect CoreGraphics and WebKit, and fix issues that affect “processing maliciously crafted” PDFs and web content. These issues, according to Apple’s characteristically vague policies, “may have been actively exploited.”

This follows up on the story that spread in July and August regarding a new hack, which University of Toronto researchers at the Citizen Lab called “ForcedEntry,” which was able to defeat BlastDoor.

It’s significant here that Apple’s new update comes one day ahead of its “California Streaming” event unveiling the iPhone 13 and other devices, and just ahead of the expected release of iOS 15. Monday’s update could thus be the last one for iOS 14, and comes at a time when it would otherwise be easy to miss. It’s reflective of the importance of the update that Apple released it at all, rather than simply kicking the can down the road and letting it get fixed with the iOS 15 rollout.

All three updates are available over-the-air at the time of writing and replace iOS 14.7.1, iPadOS 14.7.1, and WatchOS 7.6.1.

Thomas Hindmarch
Former Contributing writer
Thomas Hindmarch is a freelance writer with 20 years' experience in the gaming and technology fields. He has previously…
Samsung’s upcoming Galaxy Z Flip 8 foldable might disappoint with its battery situation
The foldable could bring small changes elsewhere, but battery convenience may remain a weak spot
Samsung Galaxy Z Flip 4.

Samsung's next flip-style foldable is shaping up as a careful update, which isn't great news for anyone hoping the company would finally tackle one of the line's most obvious weak spots. The latest leak points to the Galaxy Z Flip 8 sticking with 25W wired charging, a familiar limit that risks making the phone feel too safe in daily use.

That tradeoff has followed the Flip series for years. Samsung has sold the appeal of a compact foldable design well, but buyers have often had to accept a few practical compromises in return, and battery convenience has stayed near the top of that list.

Read more
Amazon Kindle Scribe Colorsoft review: The luxury ride to digital note-taking
It wants to be your indispensable digital diary, but it will test your Kindle loyalty, too.
Amazon Kindle Scribe

Quick Take

The Kindle Scribe Colorsoft is a new breed of e-readers from Amazon. Aside from being your reading companion, it also wants to double as your trusty note-taking device. And it does a terrific job at serving as a digital diary. The color display does a fine job of replicating the sensation of writing on paper, without any of the input lag woes you would notice on an ordinary tablet. 

Read more
Apple’s foldable is keeping Camera Control, but one-handed photography on a big foldable sounds tricky
Apple went through some serious engineering gymnastics to make it happen, but is it worth it?
Electronics, Mobile Phone, Phone

Apple's first foldable iPhone has been the subject of countless leaks, and the latest one comes from Weibo leaker Instant Digital. As reported by Notebookcheck, the leak suggests that the iPhone Fold will include the Camera Control button, despite being thinner than the iPhone Air when unfolded.

That's no small feat. Fitting the Camera Control button into a device that slim must have required some serious engineering work on Apple's part. But apparently, Apple felt it was worth it.

Read more