iOS 14.8 and other emergency Apple software updates block invasive spyware

WWDC 2021 screenshot
(Image credit: Apple)

A day before Apple is expected to release iOS 15 and other new software versions alongside the iPhone 13 launch, the company released iOS 14.8 as an emergency update to fix an exploit that allowed spyware reportedly like that used by the Israel-based NSO Group to infect iPhones, Apple Watches, and Mac computers without users needing to click on anything.

The exploit is serious enough for Apple to have been sprinting to fix it since the company was alerted to it last Tuesday by Canadian cybersecurity firm Citizen Lab, per the New York Times. In addition to iOS 14.8, Apple released iPadOS 14.8, watchOS 7.6.2, and macOS Big Sur 11.6, which users are advised to download immediately. It’s unclear if the exploit affects beta versions of upcoming software like iOS 15 (we’ve reached out to Apple to confirm).

The spyware, called Pegasus, quietly downloaded PDF files (intentionally mislabeled as .gif images) to users’ devices without their permission – and unlike other malicious code, without needing users to click on suspicious links or manually download files. Thus, this type of ‘zero click’ exploit is even more dangerous, potentially existing on devices for months without the owners noticing. 

Once the PDFs got on a device, Pegasus could activate cameras and microphones, record messages and other communications (even if encrypted) and forward that info back to the cybersurveillance firm NSO Group – and conceivably, its clients. 

Apple credited Citizen Lab for alerting the company to the issue:

"After identifying the vulnerability used by this exploit for iMessage, Apple rapidly developed and deployed a fix in iOS 14.8 to protect our users,"  Ivan Krstić, head of Apple Security Engineering and Architecture, told TechRadar over email. "We’d like to commend Citizen Lab for successfully completing the very difficult work of obtaining a sample of this exploit so we could develop this fix quickly. Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals. While that means they are not a threat to the overwhelming majority of our users, we continue to work tirelessly to defend all our customers, and we are constantly adding new protections for their devices and data.”


Analysis: Update iOS 14? In our moment of iOS 15 triumph? 

If anything sells the importance of the iOS 14.8 update, it’s that Apple chose to rush it out ahead of iOS 15, which we’re expecting to arrive on September 14 or shortly thereafter following the iPhone 13 launch. Given that every phone running iOS 14 (iPhone 6S and newer) will be able to download the new iOS 15, it’s telling that Apple pulled out the stops to make it available – and didn’t even beta test it, per 9to5Mac.

To be clear, the iOS 14.8 update is undoubtedly much smaller than iOS 15, and the same is true for the minor updates coming to iPadOS, watchOS, and macOS – so hopefully that makes it easier for folks to swallow.

As previously mentioned, it’s unclear if this exploit worked on iOS 15 public beta and other early versions of other device software; since we haven’t seen similar spyware-blocking updates for the iOS 15 and iPadOS 15 betas, we’d guess not. But Apple is getting wise to this type of exploit: the company confirmed to the New York Times that it’s adding spyware barriers to its next iOS 15 update later this year.

David Lumb

David is now a mobile reporter at Cnet. Formerly Mobile Editor, US for TechRadar, he covered phones, tablets, and wearables. He still thinks the iPhone 4 is the best-looking smartphone ever made. He's most interested in technology, gaming and culture – and where they overlap and change our lives. His current beat explores how our on-the-go existence is affected by new gadgets, carrier coverage expansions, and corporate strategy shifts.

Read more
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple iPhone 16 Review
iOS 18.3 is here with a major change to how you enable Apple Intelligence
The Apple logo is seen with the iOS 18 operating system logo in the background on a mobile device
Apple fixes Passwords app security bug with new 18.2 update
iOS 18
iOS 18: new features, compatible devices, and everything you need to know
Someone checking their credit card details online.
Apple forced to patch iOS and macOS security flaw that could have leaked your private info
Latest in iOS
Apple’s new Invites app gives iCloud Plus subscribers an easier way to organize parties – and Android fans are invited too
How to use Apple Invites: creating and responding to invitations on iPhone
iOS 18 Control Center
iOS 18.4: 5 new features to expect, including Ambient Music and Photos filtering
Apple iPhone 16 Plus Review
How to customize Camera Control on your iPhone 16: change click speed, lock exposure, and more
A hand holding an iPhone showing the logo for the Hot Tub app
The iPhone’s first official porn app has just landed in the EU – and Apple really isn’t happy about it
Three iPhones on a blue and red background running Apple Intelligence
iOS 18.3: key upgrades and bug fixes for Visual Intelligence, Apple Music, and more
iPhone 16 in a hand
Can't remember where you parked? Siri can help with this hidden iPhone feature - here's how
Latest in News
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike
An Nvidia GeForce RTX 5070
Nvidia confirms that an RTX 5070 Founders Edition is coming... just not on launch day