Recently we posted about the under-appreciated threat of Zero Day bugs and flaws in major Web Browsers. Usually, these are inadvertent mistakes or a convergence of factors that create the flaw accidentally.
The NSO Group is an example of an entirely different kind of threat, with the same or even worse impacts. Here you have a company with deep resources and expertise, selling its technology to nation state actors, to compromise the personal computing devices that we all use: welcome to the world of Spyware.
Action Needed
All at-risk users to consider enabling Lockdown Mode as Apple and Citizen Labs believe it blocks this attack.
More Details
Apple issued an update for Apple products including iPhones, iPads, Mac computers, and Apple Watches. We encourage all users to immediately update their devices. The exploit chain, referred to as BLASTPASS, was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim.
The exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim.