iOS 14.5 will blunt one of the most dangerous types of iPhone exploit

iPhone 12 Pro
(Image credit: Apple)

An imminent iOS update is set to make cyberattacks that require no input from the victim (also known as zero-click exploits) much harder to execute.

As evidenced by the beta version of iOS 14.5, Apple has changed its approach to securing code running on its phones and tablets, making it far more difficult for hackers to develop exploits that do not rely on some form of slip-up on the user’s part.

Although Apple already uses a technology known as Pointer Authentication Codes (PAC) to prevent attackers from abusing corrupted memory, this protection does not currently extend to ISA pointers, used to inform applications which portion of code to refer to.

Assuming the changes present in the beta make it into the full iOS 14.5 release, which is expected to land later this month, ISA pointers will soon come under the protection of PAC, closing off the attack vector.

iOS 14.5 security update

What makes zero-click (or 0-click) exploits so dangerous is that they do not rely on the victim clicking on a malicious link or email attachment to infect a device. And because they require no interaction on the victim’s part, the owner of the affected device is also less likely to be aware of an attack.

According to Apple, the new measures introduced with iOS 14.5 will make conducting this type of attack far more difficult, but not entirely impossible. Overall device security, the firm explained, depends on bolstering mitigation mechanisms across the board.

However, security experts are a little more bullish about the potential for iOS 14.5 to impair both zero-click attacks and sandbox attacks, which place applications in a kind of quarantine, preventing them from communicating.

Adam Donnenfeld, Security Researcher at Zimperium, told Motherboard that the steps taken by Apple will mean only the most sophisticated hackers will now be able to execute these types of attacks.

“Nowadays, since the pointer is signed, it is harder to corrupt these pointers to manipulate objects in the system. These objects were used mostly in sandbox escapes and 0-clicks,” he explained.

An anonymous iOS developer, meanwhile, suggested the iOS update will force hackers to develop entirely new methods of compromise, “because some techniques are now irretrievably lost”.

Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras