Skip to main content

Pegasus and BlastDoor are why you need to update your Apple devices immediately

The iPhone 13 may be ready to launch tomorrow, but Apple is working fast to patch a major vulnerability to its devices with a new update for iOS 14.8, iPad 14.8, and watchOS 7.6.2, none of which were given a beta test period first. While none contain major features as you might expect in advance of tomorrow’s “California Streaming” event, these are important security updates, as they contain fixes to two system vulnerabilities.

The potentially more serious one is Pegasus, which is an invasive spyware discovered by Israel’s NSO group. This “zero-click” exploit requires no input from a phone’s user to take effect, and was being used specifically against activists in Bahrain, including members of the Bahrain Centre for Human Rights. By defeating Apple’s BlastDoor security system, the ForcedEntry exploit was able to install the Pegasus spyware suite for purposes of surveillance.

Recommended Videos

According to the New York Times, the spyware is capable of infecting a wide range of Apple devices. Once infected, it can turn on your device’s camera and microphone, record messages, and access texts, emails, and calls, even ones that are encrypted.

Signal App
Signal

The second vulnerability allows attackers to get around BlastDoor, which was implemented in January in order to put a line of defense between the Messages app and the rest of iOS.

Messages have traditionally been the weakest link in iOS devices’ security, as Apple didn’t do a great job of sanitizing incoming data from other users; at its nadir, it was possible for a bad actor to take control of someone else’s iPhone by sending it a specific text message or photo. BlastDoor works by filtering out incoming bad code.

According to the official patch notes, the new updates affect CoreGraphics and WebKit, and fix issues that affect “processing maliciously crafted” PDFs and web content. These issues, according to Apple’s characteristically vague policies, “may have been actively exploited.”

This follows up on the story that spread in July and August regarding a new hack, which University of Toronto researchers at the Citizen Lab called “ForcedEntry,” which was able to defeat BlastDoor.

It’s significant here that Apple’s new update comes one day ahead of its “California Streaming” event unveiling the iPhone 13 and other devices, and just ahead of the expected release of iOS 15. Monday’s update could thus be the last one for iOS 14, and comes at a time when it would otherwise be easy to miss. It’s reflective of the importance of the update that Apple released it at all, rather than simply kicking the can down the road and letting it get fixed with the iOS 15 rollout.

All three updates are available over-the-air at the time of writing and replace iOS 14.7.1, iPadOS 14.7.1, and WatchOS 7.6.1.

Thomas Hindmarch
Former Digital Trends Contributor
Thomas Hindmarch is a freelance writer with 20 years' experience in the gaming and technology fields. He has previously…
Apple made a brilliant decision with the iPhone 16
Someone holding the iPhone 16 in its white color.

We all want the latest iPhone models to come with fancy new features, inspired new designs, and the best camera you can get. While the iPhone 16 series looks good, big changes were unfortunately not on the agenda this year.

However, the complete lack of change in one important aspect of the iPhone 16 was very welcome indeed — and it gives Apple the edge against the competition this year. I’m talking about the price.
No price increase

Read more
Can open-ear headphones really cancel noise? Apple’s AirPods 4 surprised me
AirPods 4 on a stand at the Apple Glowtime event on September 9, 2024.

For years, the biggest feature separating Apple's entry-level AirPods from the AirPods Pro has been active noise cancellation, also known as ANC. When I learned that Apple might outfit a version of its new AirPods 4 earbuds with ANC, I was skeptical. Open-ear designs, which don't fully obstruct your ear canal, make it pretty tough to seal out noise. But now that I’ve had a chance to hear the open-ear AirPods 4 in action, I must admit, I’m surprised at how effective they are.

You may also want to reconsider if you tend to dismiss the idea of active noise canceling in an open-ear earbud.

Read more
The Apple Watch Series 10 is a bigger upgrade than you think
Someone holding the Apple Watch Series 10.

We didn't know much about the Apple Watch Series 10 going into Apple's latest hardware event. Other than a handful of small leaks here and there, this year's Apple Watch was a surprisingly well-kept secret. Now that it's official and I've had a chance to use it, was it worth that tight-lipped secrecy? It may not seem so on the surface, but I think it was.

At first glance, the Apple Watch Series 10 doesn't look very different from the Apple Watch Series 9. You still have a squircle display, the Digital Crown, the same watch band system, etc. Some rumors suggested we'd get a complete makeover of the Apple Watch in honor of the wearable's 10th anniversary, but that didn't exactly happen. However, don't let that fool you into thinking the Apple Watch Series 10 is a simple rehash of the Series 9. There are some pretty significant hardware changes here, even if they aren't immediately apparent.

Read more