Skip to main content

Apple has patched critical iPhone exploits mentioned in the Wikileaks CIA dump

iphone iphishing scam lifestyle head
Image used with permission by copyright holder
The Central Intelligence Agency was implicated this week in a clandestine effort to defeat encryption on phones, laptops, smart TVs, and even connected cars. Among the startling revelations was the agency’s hoarding of zero day exploits — unpatched bugs — that could grant intelligence agents access to encrypted iPhones. But there may be less cause for alarm than the leaked documents led many publications to believe.

One Wednesday, a spokesperson for Apple told members of the press that a number of security loopholes were closed in the latest version of iOS, the iPhone’s operating system.

“Our products and software are designed to quickly get security updates into the hands of our customers, with nearly 80 percent of users running the latest version of our operating system,” an Apple spokesperson told Motherboard. “While our initial analysis indicates that many of the issues leaked were patched in the latest iOS, we will continue work to rapidly address any identified vulnerabilities.”

Wikileaks, which published internal CIA documents earlier this week, didn’t distribute any of the exploits. But leaked spreadsheets detailed several of the methods circulated among the world’s top intelligence agencies, including the CIA, FBI, and GCHQ, the U.K.’s electronics intelligence agency.

Earth/Eve was an exploit purchased by the NSA and later shared with the CIA. GCHQ discovered a critical zero day code named Nandao. The CIA uncovered a bug that allowed agents to remotely control a targeted device. And the FBI’s Remote Operations Unit, one of the Bureau’s hacking divisions, discovered an iOS 7 hack.

Other attacks were mentioned in a user guide for “MCNUGGET,” a tool that breaks encryption on iOS 8.0-8.1.3 devices. Another user guide referenced “DRBOOM,” a script that lets an attacker with physical access to an iOS 7-8.2 device install persistent malware. And still other documents listed exploits that have been publicly disclosed, including one by Chinese jailbreaking team Pangu and iOS security researcher Stefan Esser.

In all, the documents named 14 separate exploits and attacks.

Just because Apple has patched a few of iOS’s vulnerabilities doesn’t mean your phone is now safe from prying eyes. The CIA has reportedly broken the security of popular chat apps like WhatsApp, Signal, Telegram, Weibo, and others by intercepting messages and photos before they could be encrypted. And Android phones aren’t immune — according to Wikileaks, the CIA had 24 weaponized Android “zero day” software programs by the end of 2016.

Still, updating your iPhone to the latest software version will reduce some potential vulnerability, at the very least.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
6 upcoming products that will make 2024 a huge year for Apple
Apple CEO Tim Cook standing in front of four Vision Pro headsets.

Next year is set to be a bumper year for Apple fans, with the company planning a huge range of new and updated products in 2024. With rumors pointing to significant changes across the board, it could be a great time to upgrade.

We’ve sorted our way through the rumors to determine which upcoming Apple products we’re most excited about. If all of these devices live up to the hype in 2024, there will be a whole lot to look forward to.
Vision Pro

Read more
Shopping at Apple this holiday season? You should know this
A man checks his phone in an Apple retail store in Grand Central Terminal.

If you splash out on an Apple product during the upcoming holiday season -- whether it’s an iPhone, iPad, Mac, smartwatch, earbuds, or some other item -- then it’s important to know the terms and conditions in the event that you want to return it.

For most of the year, Apple offers a refund if you return an unwanted item within two weeks of buying it. But during the hectic holiday season when we might be away or busy with friends and family, it usually extends the period to make the returns process more convenient.

Read more