New iOS security flaw means you should update your iPhone right now

iPhone 6s

Apple released a critical iOS update today to fix an exploit that allowed malware to be installed on an iPhone with a single tap.

A report from Vice reveals the details of the exploit used to target Emirati human rights activist Ahmed Mansoor. Mansoor received a suspicious text that read, "New secrets about torture of Emiratis in state prisons" and included a link.

Instead of clicking on the link, though, Mansoor forwarded the message to Citizen Lab, a Toronto-based digital rights watchdog.

The text, it turns out, was malware that allowed an iPhone to be jailbroken in one tap. The malware, codenamed Pegasus, let an attacker steal and intercept all data on an iPhone. Calls could be intercepted, contacts lists exposed and text messages stolen.

NSO Group marketing materials

Image credit: WikiLeaks | NSO marketing materials that show what info Pegasus is able to capture.

Citizen Lab collaborated with cyber security company Lookout to dissect the malware and discovered its origins. The malware was created and distributed by a company called NSO Group, known for selling its spyware to governments. "[They're] basically a cyber arms dealer," said Lookout Vice President of Research Mike Murray.

NSO told Vice its malware is designed to "help make the world a safer place by providing authorized governments with technology that helps them combat terror and crime." But for journalists and activists living under a corrupt government, this inspires little confidence.

Update your phone now

Today's iOS 9.3.5 update patches the exploits used by NSO. Apple recommends all iPhone users update as soon as possible to avoid being a victim of this type of malware.

It pays to keep your phone's security up to date and to use common sense when receiving dubious links. Although news of Pegasus is alarming, iOS is still one of the most secure mobile operating systems for consumers, according to Dan Guido, CEO of cybersecurity firm Trail Of Bits, speaking to Vice.

iOS 9.3.5 update

Android's security has often lagged as a result of outdated software running on a majority of handsets. Android 6.0 Marshmallow still only makes up 15.2% of all Android handsets as of August 2016, according to Android Police.

Note that Android 6.0 is already one version behind Android 7.0 Nougat, which is only available on select Nexus phones right now.

While Pegasus may be patched today, it's a constant race between companies such as NSO and the likes of Apple, Google and Microsoft. It's up to software makers to stay one step ahead, and users to stay vigilant.

TOPICS
Lewis Leong
Lewis Leong is a freelance writer for TechRadar. He has an unhealthy obsession with headphones and can identify cars simply by listening to their exhaust notes.
Latest in iOS
iPhone Home Screen
iOS 19 is set to usher in a major redesign – here are 4 things being tipped for the upcoming overhaul
Three iPhones on a green and blue background showing trails on Apple Maps
iOS 18.4 will give your iPhone a much-needed maps upgrade – but only if you're in the EU
iOS 18 Control Center
iOS 19: the 3 biggest rumors so far, and what I want to see
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Apple’s new Invites app gives iCloud Plus subscribers an easier way to organize parties – and Android fans are invited too
How to use Apple Invites: creating and responding to invitations on iPhone
iOS 18 Control Center
iOS 18.4: 5 new features to expect, including Ambient Music and Photos filtering
Latest in News
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
An image of the Nintendo Switch 2
Nintendo Switch 2 likely to have AI upscaling similar to PS5 Pro’s PSSR according to patent, and it could be a gamechanger for graphics on the upcoming console
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Intel Lunar Lake concept
Intel's Panther Lake processors won't arrive until Q1 2026 - corroborates previous delay rumors despite former Intel CEO's promise of 2025 launch
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, March 18 (game #1149)