IPhone users please update iOS 16.6.1. Apple fixes 2 vulnerabilities used in Pegasus spyware.
CTOnews.com Sept. 8 news, Citizen Lab released a security blog today, saying that Apple released today's iOS 16.6.1 and other version updates, fixed two security vulnerabilities, these two vulnerabilities were used by the NSO Group Group Pegasus monitoring software.
Citizen Lab said in a blog post that the tracking numbers of these two vulnerabilities are CVE-2023-41064 and CVE-2023-41061, respectively. Attackers use the above vulnerabilities to create pictures containing malicious code and distribute them through PassKit attachments.
CTOnews.com Note: Pegasus is a malicious application developed by NSO Group to monitor and steal relevant information, mainly aimed at journalists, dignitaries and various activists.
Citizen Lab said the exploit chain is BLASTPASS, and in iOS 16.6 and earlier, it is possible to run malicious code without victim interaction.
Citizen Lab urges iPhone users to upgrade the iOS 16.6.1 update as soon as possible and recommends users who need to activate Lockdown mode.
The list of affected devices includes:
IPhone 8 series and subsequent models
IPad Pro (all models), iPad Air Generation 3 and subsequent models, iPad Generation 5 and newer models, iPad mini Generation 5 and subsequent models
Mac running macOS Ventura
Apple Watch Series 4 and subsequent models.