iOS 14.5 to Make Zero-Click Attacks ‘Significantly Harder’

Apple’s impending iOS and iPadOS 14.5 update will make zero-click attacks considerably more difficult by extending PAC security provisions, according to Motherboard.

Apple has made a change to the way in which it secures its code in the latest betas of iOS 14.5 and iPadOS 14.5 to make zero-click attacks much harder. The change, spotted by security researchers, has now been confirmed by Apple and is slated to be included in the final update.

Zero-click attacks allow hackers to break into a target without the need for victim interaction, such as clicking a malicious phishing link. Zero-click attacks are therefore considerably harder for targeted users to detect and are considered to be much more sophisticated.

Since 2018, Apple has used Pointer Authentication Codes (PAC) to prevent attackers from leveraging corrupted memory to inject malicious code. Cryptography is applied to authenticate pointers and validate them before they are used. ISA pointers instruct a program about what code it should use when it runs on iOS. By using cryptography to sign these pointers, Apple is now extending PAC protection to ISA pointers.

“Nowadays, since the pointer is signed, it is harder to corrupt these pointers to manipulate objects in the system. These objects were used mostly in sandbox escapes and zero-clicks,” security firm Zimperium’s Adam Donenfeld told Motherboard. The change will “definitely make zero-clicks harder. Sandbox escapes too. Significantly harder.” Sandboxes aim to isolate applications from each other to stop code from a program interacting with the wider operating system.

While zero-clicks will not be eradicated through this change, many of the exploits used by hackers and governmental organizations will now be “irretrievably lost.” Hackers will now need to find new techniques to implement zero-click attacks on iPhone and iPad, but the security improvements to ISA pointers are likely to make a significant impact on the overall number of attacks on these devices.Related Roundups: iOS 14, iPadOS 14
This article, “iOS 14.5 to Make Zero-Click Attacks ‘Significantly Harder'” first appeared on MacRumors.com

Discuss this article in our forums

MacRumors-All?d=6W8y8wAjSf4 MacRumors-All?d=qj6IDK7rITs

Related posts

Latest posts

Here’s how to watch Sony’s Xperia 1 VII launch event

Sony’s next phone, the Xperia 1 VII, will be unveiled on Tuesday, May 13! You can catch all the action live on that day beginning at 11 a.m. Japan time, which is 10 p.m. on May 12 in EDT. You can watch the event on YouTube using this link. If you’re a Sony fan, you […]

HP’s smallest gaming PC with RTX 3050 is on sale today at $150 off

The HP Omen 16L, the brand's smallest gaming PC, is on sale today, with this configuration featuring the Nvidia GeForce RTX 3050 graphics card down by $150.

The latest Google Pixel 9 deal from Amazon UK gives you a FREE pair of Pixel Buds Pro 2

As part of its sitewide Tech Week sale, Amazon is giving away a free pair of Google Pixel Buds Pro

Samsung cranks up Galaxy S25 production with tariff clouds on the horizon

Samsung is racing to pump out S25s before Trump’s tariffs kick in.

Fiio’s K17 is the obvious upgrade to the K9 Pro

The K17 combines a stunning retro design with all the features you need in a high-end DAC.

The Galaxy S25 Edge gets leaked again ahead of next week’s launch

Marketing materials for the upcoming Galaxy S25 Edge have leaked, revealing notable camera specs and design elements.

Walmart’s leaked Onn 4K Plus offers affordable Google TV Streaming

A now-deleted Walmart listing revealed the upcoming Onn 4K Plus streaming device, powered by Google TV and priced under $30.

News Weekly: Google leaks Material 3 design, Galaxy S25 Edge gets a launch date, One UI 8 leaks, and more

This week, Google ends up leaking its new UI, Samsung Galaxy S25 Edge set to launch next week, One UI

Microsoft taps ex-Meta marketing boss to boost Copilot AI

A former Meta and Time Warner executive has snagged the role of global creative director for Microsoft AI.

Why are we obsessed with charging speeds?

If we're really lucky, we might get a phone battery that charges more quickly. Otherwise, I think we're stuck with