Skip to main content

Apple just fixed an iMessage bug that researchers called easily exploitable

how to save text messages
Kritchanut/Shutterstock
Your chat history on iMessage just went through a period when it was not altogether safe, but now, all wrongs have been righted thanks to an OS X update. A major issue in iMessage was recently fixed by Apple, preventing hackers and other ne’er-do-wells from pulling victims’ message histories.

It turns out that, prior to the fix, hackers had the ability to send iMessagers special links that, when clicked, granted access to the otherwise encrypted messages sent between iPhone users. In fact, so simple was the vulnerability that security researchers at Bishop Fox said that, “You don’t need a graduate degree in mathematics to exploit it, nor does it require advanced knowledge of memory management, shellcode, or ROP chains.” But now, Apple has addressed the issue, and your correspondence is safe once more.

While the problem has been addressed, it does nothing for the security reputation of Apple, who has recently had their iPhone hacked by the FBI as well as by researchers at John Hopkins, who published their own findings on iPhone vulnerabilities just a few weeks ago. This latest hole was discovered by researchers Joe DeMesy and Shubham Shah of Bishop Fox, along with Matt Bryant of Uber’s security team. The trio told Apple before they told the public, and thus far, there’s no evidence to suggest that any iMessage user fell victim to an attack as a result from the security flaw.

According to VentureBeat, an iMessage attack of this nature would have relied upon “javascript code in place of an iMessage URL in a classic cross-scripting attack.” The vulnerability was addressed with the CVE-2016-1764 update, which went into effect last month, so users now have no reason to worry. Of course, any sort of security flaw within Apple generally causes some sort of ruckus, but the company has yet to respond to requests for comment. In the meantime, however, rest assured that the latest version of Apple’s software contains no such holes — so if you haven’t yet updated, hop to.

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Apple has just fixed one of the weirder iPhone bugs
The Apple iPhone 15 Pro Max's camera module.

Apple has squashed a bug on the iPhone and iPad that caused deleted photos to reappear on the devices.

As smartphone bugs go, this was surely one of the more bizarre ones. Reports of the strange issue began to surface following Apple’s rollout of iOS 17.5 last week.

Read more
iOS 17.5 just launched with a huge security feature for your iPhone
Apple iPhone 15 Plus and Apple iPhone 15 Pro Max seen from the back.

Apple iPhone 15 Plus (left) and Apple iPhone 15 Pro Max Andy Boxall / Digital Trends

Apple has just released the iOS 17.5 update for iPhones, which brings a host of new features. For European Union residents, it enables Web Distribution, which means you can sideload apps from the internet and won’t be limited to the App Store.

Read more
AT&T just made it a lot easier to upgrade your phone
AT&T Storefront with logo.

Do you want to upgrade your phone more than once a year? What about three times a year? Are you on AT&T? If you answered yes to those questions, then AT&T’s new “Next Up Anytime” early upgrade program is made for you. With this add-on, you’ll be able to upgrade your phone three times a year for just $10 extra every month. It will be available starting July 16.

Currently, AT&T has its “Next Up” add-on, which has been available for the past several years. This program costs $6 extra per month and lets you upgrade by trading in your existing phone after at least half of it is paid off. But the new Next Up Anytime option gives you some more flexibility.

Read more