{"id":653,"date":"2019-09-01T14:10:39","date_gmt":"2019-09-01T08:25:39","guid":{"rendered":"https:\/\/www.meromauka.com\/news\/?p=653"},"modified":"2019-09-01T14:10:42","modified_gmt":"2019-09-01T08:25:42","slug":"google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones","status":"publish","type":"post","link":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/","title":{"rendered":"Google reveals major iPhone security flaws that let websites hack phones"},"content":{"rendered":"\n<p>Malicious websites could access files, messages, and location data<\/p>\n\n\n\n<p>Security researchers working in Google\u2019s Project Zero team say they have discovered a number of hacked websites which used previously undisclosed security flaws to\u00a0indiscriminately attack any iPhone that visited them.\u00a0<em>Motherboard<\/em>\u00a0reports\u00a0that the attack could be one of the largest ever conducted against iPhone users. If a user visited one of the malicious websites using a vulnerable device, then their personal files, messages, and real time location data could be compromised. After reporting their findings to Apple, the iPhone manufacturer patched the vulnerabilities earlier this year.<\/p>\n\n\n\n<p><em>Motherboard<\/em>&nbsp;notes that the attack could have allowed the sites to install an implant with access to an iPhone\u2019s keychain. This would have given the attackers access to any credentials or certificates contained within it, and could also allow them to access the databases of seemingly secure messaging apps like WhatsApp and iMessage. Despite these apps using end-to-end encryption for the transfer of messages, if an end device was compromised by this attack, then an attacker could access previously encrypted messages in plain text.IOS VERSIONS 10 THROUGH 12 WERE AFFECTED<\/p>\n\n\n\n<p>The attack is notable because of how indiscriminate it is.&nbsp;<em>Motherboard<\/em>&nbsp;notes that other attacks are typically more targeted, with individual links being sent to targets. In this case, simply visiting a malicious site could be enough to be attacked, and for an implant to be installed on a device. The researchers estimate that the compromised sites were visited by thousands of visitors each week.<\/p>\n\n\n\n<p>The implant installed by the malicious sites would be deleted if a user rebooted their phone. However, the researchers say that since the attack compromises a device\u2019s keychain, then the attackers could gain access to any authentication tokens it contains, and these could be used to maintain access to accounts and services long after the implant has disappeared from a compromised device.<\/p>\n\n\n\n<p>In total, the researchers say they discovered 14 vulnerabilities across five different exploit chains, including one which was unpatched at the time the researchers discovered it. iOS versions 10 through 12 were all affected by the vulnerabilities, which the researchers say indicates that the attackers were attempting to hack users over at least two years.<\/p>\n\n\n\n<p>The team says they contacted Apple to report the vulnerability back in February, and gave the company just seven days to patch it.\u00a0<em>TechCrunch\u00a0<\/em>notes\u00a0that this is a far shorter deadline than the typical 90-day window usually given by researchers, and likely reflects how serious the vulnerabilities are. Apple patched the vulnerabilities with iOS 12.1.4, the same update that fixed a major\u00a0FaceTime security flaw.<\/p>\n\n\n\n<p>Although the vulnerabilities have now been patched, the researchers note that there are likely to be more out there that they\u2019re yet to discover. \u201cFor this one campaign that we\u2019ve seen, there are almost certainly others that are yet to be seen,\u201d they write. You can find full details of the exploits in the\u00a0researcher\u2019s blog post.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malicious websites could access files, messages, and location data Security researchers working in Google\u2019s Project&#8230;<\/p>\n","protected":false},"author":3,"featured_media":34,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-653","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Google reveals major iPhone security flaws that let websites hack phones | Buy sell anything in Nepal<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Google reveals major iPhone security flaws that let websites hack phones | Buy sell anything in Nepal\" \/>\n<meta property=\"og:description\" content=\"Malicious websites could access files, messages, and location data Security researchers working in Google\u2019s Project...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\" \/>\n<meta property=\"og:site_name\" content=\"Buy sell anything in Nepal\" \/>\n<meta property=\"article:published_time\" content=\"2019-09-01T08:25:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-09-01T08:25:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1275\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\"},\"author\":{\"name\":\"\",\"@id\":\"\"},\"headline\":\"Google reveals major iPhone security flaws that let websites hack phones\",\"datePublished\":\"2019-09-01T08:25:39+00:00\",\"dateModified\":\"2019-09-01T08:25:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\"},\"wordCount\":507,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/f799147ea0d17e6823f8d408f5c76042\"},\"image\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg\",\"articleSection\":[\"Tech\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\",\"url\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\",\"name\":\"Google reveals major iPhone security flaws that let websites hack phones | Buy sell anything in Nepal\",\"isPartOf\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg\",\"datePublished\":\"2019-09-01T08:25:39+00:00\",\"dateModified\":\"2019-09-01T08:25:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage\",\"url\":\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg\",\"contentUrl\":\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg\",\"width\":1920,\"height\":1275},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.meromauka.com\/news\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Google reveals major iPhone security flaws that let websites hack phones\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.meromauka.com\/news\/#website\",\"url\":\"https:\/\/www.meromauka.com\/news\/\",\"name\":\"Buy Sell anything in Nepal\",\"description\":\"MeroMauka News\",\"publisher\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/f799147ea0d17e6823f8d408f5c76042\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.meromauka.com\/news\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/f799147ea0d17e6823f8d408f5c76042\",\"name\":\"meromauka\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2019\/07\/LOGO.png\",\"contentUrl\":\"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2019\/07\/LOGO.png\",\"width\":250,\"height\":39,\"caption\":\"meromauka\"},\"logo\":{\"@id\":\"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/image\/\"},\"sameAs\":[\"https:\/\/www.meromauka.com\"]},{\"@type\":\"Person\",\"@id\":\"\",\"url\":\"https:\/\/www.meromauka.com\/news\/author\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Google reveals major iPhone security flaws that let websites hack phones | Buy sell anything in Nepal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/","og_locale":"en_GB","og_type":"article","og_title":"Google reveals major iPhone security flaws that let websites hack phones | Buy sell anything in Nepal","og_description":"Malicious websites could access files, messages, and location data Security researchers working in Google\u2019s Project...","og_url":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/","og_site_name":"Buy sell anything in Nepal","article_published_time":"2019-09-01T08:25:39+00:00","article_modified_time":"2019-09-01T08:25:42+00:00","og_image":[{"width":1920,"height":1275,"url":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"","Estimated reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#article","isPartOf":{"@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/"},"author":{"name":"","@id":""},"headline":"Google reveals major iPhone security flaws that let websites hack phones","datePublished":"2019-09-01T08:25:39+00:00","dateModified":"2019-09-01T08:25:42+00:00","mainEntityOfPage":{"@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/"},"wordCount":507,"commentCount":0,"publisher":{"@id":"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/f799147ea0d17e6823f8d408f5c76042"},"image":{"@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage"},"thumbnailUrl":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg","articleSection":["Tech"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/","url":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/","name":"Google reveals major iPhone security flaws that let websites hack phones | Buy sell anything in Nepal","isPartOf":{"@id":"https:\/\/www.meromauka.com\/news\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage"},"image":{"@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage"},"thumbnailUrl":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg","datePublished":"2019-09-01T08:25:39+00:00","dateModified":"2019-09-01T08:25:42+00:00","breadcrumb":{"@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#primaryimage","url":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg","contentUrl":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg","width":1920,"height":1275},{"@type":"BreadcrumbList","@id":"https:\/\/www.meromauka.com\/news\/google-reveals-major-iphone-security-flaws-that-let-websites-hack-phones\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.meromauka.com\/news\/"},{"@type":"ListItem","position":2,"name":"Google reveals major iPhone security flaws that let websites hack phones"}]},{"@type":"WebSite","@id":"https:\/\/www.meromauka.com\/news\/#website","url":"https:\/\/www.meromauka.com\/news\/","name":"Buy Sell anything in Nepal","description":"MeroMauka News","publisher":{"@id":"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/f799147ea0d17e6823f8d408f5c76042"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.meromauka.com\/news\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":["Person","Organization"],"@id":"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/f799147ea0d17e6823f8d408f5c76042","name":"meromauka","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/image\/","url":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2019\/07\/LOGO.png","contentUrl":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2019\/07\/LOGO.png","width":250,"height":39,"caption":"meromauka"},"logo":{"@id":"https:\/\/www.meromauka.com\/news\/#\/schema\/person\/image\/"},"sameAs":["https:\/\/www.meromauka.com"]},{"@type":"Person","@id":"","url":"https:\/\/www.meromauka.com\/news\/author\/"}]}},"jetpack_featured_media_url":"https:\/\/www.meromauka.com\/news\/wp-content\/uploads\/2018\/07\/bar-local-cong-ireland-38286-1-1.jpeg","_links":{"self":[{"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/posts\/653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/comments?post=653"}],"version-history":[{"count":1,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/posts\/653\/revisions"}],"predecessor-version":[{"id":654,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/posts\/653\/revisions\/654"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/media\/34"}],"wp:attachment":[{"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/media?parent=653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/categories?post=653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.meromauka.com\/news\/wp-json\/wp\/v2\/tags?post=653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}