Update your iPhone now – Apple just fixed a big iOS security flaw

An iPhone on a yellow background showing an iOS update message
(Image credit: Future)

Own an iPhone or iPad that's running iOS 16 or iPadOS 16? You should manually update your software right now – Apple has just released an important security fix that could stop hackers from installing powerful spyware on your device.

The vulnerability has only just been discovered, which means Apple has rushed out a fix in the form of iOS 16.6.1 and iPadOS 16.6.1. It's wise to install these updates manually even if you have automatic updates turned on, rather than waiting for them to install overnight. To do this, go to Settings > General > Software Update on your iPhone or iPad, and tap 'download and install'.

The update is available for all iPhones from the iPhone 8 onwards, all iPad Pro models, the iPad Air 3rd generation (from 2019) and later, the iPad 5th generation (from 2017) onwards, and the iPad Mini 5th gen (from 2019) or later. The security flaw was discovered by Citizen Lab, which is a spyware research group in the University of Toronto.

The reason why this particular iOS vulnerability is so noteworthy – and important to fix – is because it allowed the remote installation of the NGO Group's Pegasus mercenary spyware, which essentially allows governments spy on citizens. As Citizen Lab explained, the exploit could do this "without any interaction from the victim".

The precise mechanics of how this happened to an employee of an international civil society organization – the incident that raised the alarm bells – aren't clear. But it involved the coding framework behind Apple Pay and Wallet being hacked with attachments containing malicious images, which were sent from the attacker's iMessage account.

Citizen Lab says that it'll publish "a more detailed discussion of the exploit chain in the future". But for now we'd recommend updating your iPhone or iPad as soon as possible. The spyware research lab also says that Apple's new Lockdown Mode, which has been designed to protect its devices against "extremely rare and highly sophisticated cyber attacks" is also effective against the attack.

If you think you're particularly vulnerable to being targeted, you can turn on Lockdown Mode by going to Settings > Privacy & Security, then scrolling down to LockDown Mode under 'Security', toggling it on then tapping 'Turn On & Restart'. This is an extreme measure, though, and unnecessary for most people, as it'll limit apps, website and other features on your phone.

Keeping your iPhone secure

An iPhone on a yellow background showing a security update being installed

(Image credit: Future)

While Apple devices continue to have a reputation for being superior to rivals in terms of cybersecurity, iOS security flaws have increasingly hit the headlines in recent years.

This led Apple to announced a new Rapid Security Response feature at WWDC 2022, which lets you download security patches as soon as they’re available and without even needing to reboot your device.

The downside is that, on rare occasions, these can also automatically update devices to flawed software patches, so it's possible to remove the feature. To do this, go to General > Software Update > Automatic Updates, then toggle the 'Security Responses & System Files' to off.

We'd still recommend keeping that feature on, though, and Apple didn't use it for these latest iOS 16.6.1 and iPadOS 16.6.1 updates. Those have been pushed out as  standard system updates, but it's worth manually installing them even if you have automatic updates turned on, rather than waiting for that to happen overnight.

While the targets of these kinds of spyware attacks are naturally likely to be government officials, they can open the door to follow-up attacks from other hackers, so keeping your phone up to date is good for the health of the overall operating systems.

You might also like

Mark Wilson
Senior news editor

Mark is TechRadar's Senior news editor. Having worked in tech journalism for a ludicrous 17 years, Mark is now attempting to break the world record for the number of camera bags hoarded by one person. He was previously Cameras Editor at both TechRadar and Trusted Reviews, Acting editor on Stuff.tv, as well as Features editor and Reviews editor on Stuff magazine. As a freelancer, he's contributed to titles including The Sunday Times, FourFourTwo and Arena. And in a former life, he also won The Daily Telegraph's Young Sportswriter of the Year. But that was before he discovered the strange joys of getting up at 4am for a photo shoot in London's Square Mile. 

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
An iPhone with a 10:30am alarm ringing next to an Apple Watch that displays the time as 12:42pm
Apple warns "extremely sophisticated attack" hits iPhones and iPads, so update now
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple iPhone 16 Review
iOS 18.3 is here with a major change to how you enable Apple Intelligence
iOS 18
iOS 18: new features, compatible devices, and everything you need to know
Latest in iPhone
The Apple iPhone 16e held at a slant at a window
From iPhone to Android and (almost) back again – the iPhone 16e failed to lure me back to iOS
Apple iPhone 16 Pro Max REVIEW
The latest iPhone 17 Pro Max leak may have given us another look at its upcoming redesign
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
Apple iPhone 16 Plus Review
iPhone 17 Air leaks suggest it'll get next-gen battery – and offset the 17 Pro Max's weight gains
Two hands holding the Tecno Spark Slim phone
The world’s thinnest phone was just revealed, but a new iPhone 17 Air leak suggests it could be even slimmer
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Ray-Ban smart glasses with the Cpperni logo, an LED array, and a MacBook Air with M4 next to ecah other.
ICYMI: the week's 7 biggest tech stories from Twitter's massive outage to iRobot's impressive new Roombas
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today