April 25, 2024
iOS 9.3.5 Fixes Vulnerabilities Used By Government Agencies to Spy on Various Targets

iOS 9.3.5 Fixes Vulnerabilities Used By Government Agencies to Spy on Various Targets

Posted August 26, 2016 at 12:06am by iClarified
Apple's release of iOS 9.3.5 today fixes three vulnerabilities used by government agencies to spy on dissidents, journalists, criminals, and other targets.

The New York Times reports that the vulnerabilities were discovered and sold to authorities by the Israeli security company NSO Group.

Investigators discovered that a company called the NSO Group, an Israeli outfit that sells software that invisibly tracks a target’s mobile phone, was responsible for the intrusions. The NSO Group’s software can read text messages and emails and track calls and contacts. It can even record sounds, collect passwords and trace the whereabouts of the phone user.


Zamir Dahbash, an NSO Group spokesman, said in an email, “The company sells only to authorized governmental agencies, and fully complies with strict export control laws and regulations.”

Dahbash also noted that NSO Group does not operate any of its systems and requires that its customers use its products in a “lawful manner.”

“Specifically, the products may only be used for the prevention and investigation of crimes.”

The vulnerabilities were brought to light after UAE human rights activist Ahmed Mansoor received some suspicious text messages. He shared the messages with Citizen Lab who then brought in Lookout to help examine the code. Together they discovered the three previously unknown iOS vulnerabilities and informed Apple about their existence.


Apple fixed the holes 10 days after a tip from Bill Marczak at Citizen Lab and John Scott Railton at Lookout.

“We advise all of our customers to always download the latest version of iOS to protect themselves against potential security exploits,” said Fred Sainz, an Apple spokesman.

You can download iOS 9.3.5 from here.

Read More


iOS 9.3.5 Fixes Vulnerabilities Used By Government Agencies to Spy on Various Targets
Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (15)
You must login or register to add a comment...
user
user - August 28, 2016 at 4:31pm
I think the new version contains back doors ... in purpose with Apple permission
clown
clown - August 27, 2016 at 5:50am
Disable java
tar
tar - August 26, 2016 at 10:20pm
what if they are not vulnerabilities, and they are actually back doors, they were just found out by a 3rd party. of course apple would never admit to such a thing, and just to save face, they would condemn such actions and put on some legal show up ;) can you really 100% trust apple to not have done that :p
daf
daf - August 26, 2016 at 4:10pm
important enough to lose JB. updated straight away
Marbles
Marbles - August 26, 2016 at 9:42am
So apple as been hacked by it's own government. Expected. What about IOS 10 testers ? Are they vulnerable too....... And has an update put out there to protect them ?
JuergenWest
JuergenWest - August 26, 2016 at 11:36pm
Apple is not Israeli.
lepaka
lepaka - August 26, 2016 at 6:46am
they dont exist, until they are found :) that it is the human nature, it is not a hole in the iOS, but in the human brains that are always looking the way out of here.
tar
tar - August 26, 2016 at 6:32am
I thought those vulnerabilities used by government agencies to spy, listen etc.. didn't exist :blink: :blink:, and I think no more of those vulnerabilities exist any more :blink: :blink:
clown
clown - August 26, 2016 at 3:57am
The odd story is they released 9.3.4 possible knowingly these were in existence , months ago in some articles state.. why did they not fix them in 9.3.3 ... Let alone 9.3.4 The release of 9.3.4 was solely to block the JB , but the fixes were not applicable 9.3.3 ? when other articles said they were aware for months of there existence.? Why were they not fixed in 9.3.3 . Where they waiting so people would be included to release a JB for 9.34 , and with the planned update of 9.3.5 they could block both at the same time( included the fix for the three bugs) .
JuergenWest
JuergenWest - August 26, 2016 at 11:38pm
Possibly different teams working on this. One was to block public jailbreak and other to block spy attacks. Basically same thing though.
SayingWhatEveryonesThinking
SayingWhatEveryonesThinking - August 26, 2016 at 3:49am
This was more important than a minor bug, and they fixed it pretty fast. Get your priorities straight; Apple did a great job here.
clown
clown - August 26, 2016 at 3:19am
If this is available on all iOS versions. Know you know why someone could not use their devices.
City023
City023 - August 26, 2016 at 12:15am
Apple advises to always download to avoid the latest exploit?....Smfh how about to fix the latest or most recent bugs. Can they stop worrying about the JB team and better their iOS?
JollySonX
JollySonX - August 26, 2016 at 4:41pm
Id say something that can allow people access to mail, messages and record audio without consent is a pretty big bug, which they have fixed 10 days after finding out about it. I'd say it is a big improvement to the iOS, it might not be a cool new feature, but it's still a fix ( a very important fix at that )
JuergenWest
JuergenWest - August 26, 2016 at 11:41pm
I agree, this fix was very important. Blocks invasive exploit while 9.3.4 blocked jailbreak which while an exploit, was a voluntary hole that end user would choose to be subjected to. Spying however, most never even know it's happening till too late.
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Monterey
Where to Download macOS Ventura
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS