Skip to main content

Recently patched vulnerabilities provided hackers complete access to iPhones

A new report from a mobile security firm has highlighted a series of vulnerabilities in previous versions of iOS that, when used in the right context, could give an attacker complete control of a user’s device. The findings were published by Zimperium, and relate to two components in particular: the IOSurface and AppleAVE kernel extensions.

These components are responsible for driving a device’s display and allowing hardware acceleration for videos, respectively — though Zimperium has outlined eight ways in which they can be used to compromise an iPhone or iPad. The vulnerabilities concern the elevation of privileges, so unscrupulous parties can be granted free rein over the system. Once they’re in, a hacker can access a variety of personally identifiable information, like the device’s GPS location data, contacts, microphone, and even photos.

Recommended Videos

The IOSurface extension in particular has been previously linked to jailbreak methods, and with the release of iOS 10.3.2, Apple has patched the issues. However, users of older devices are still left unprotected. According to Zimperium’s Adam Donenfeld, who discovered the vulnerabilities, the exploits are so discreet that they can be performed without the user’s knowledge.

“Before the patch, the only way for a user to guard itself was to install a third-party mobile protection solution,” Donenfeld told Digital Trends. “Unless patched, without a third-party mobile protection solution there’s no way for a user to know whether he’s being attacked.”

Thankfully, Donenfeld noted that Apple has acted swiftly in issuing fixes. Zimperium notified the company of its findings toward the end of March, and Apple pushed out iOS 10.3.2 to devices in mid-May. The oldest iPhone currently supported with updates is the iPhone 5, meaning the wide majority of current iOS users have been covered. Zimperium will publish an expanded proof-of-concept explaining the vulnerabilities in greater detail soon, but the report is currently being delayed at Apple’s request.

Mobile devices carry unique risks. That’s the reason why firms like Zimperium exist — to address the concerns of smartphone and tablet users, who face a very different threat from their desktop counterparts. One of the dangers Donenfeld identifies is the behavior of many mobile devices in automatically connecting to available public Wi-Fi networks.

“Network-based threats are significant and far too easy to execute,” Donenfeld said. “Plus, malware in many forms has grown at an alarming rate in recent years. We’ve seen an increasing number of mobile vulnerabilities — such as Stagefright — being discovered.”

Despite manufacturers’ and researchers’ best efforts, Donenfeld doesn’t expect the rising tide of crime to turn anytime soon.

“Mobility provides a huge number of assets with much less risk of discovery and prosecution than traditional crimes, so it is only logical that mobile threats will continue to grow.”

Adam Ismail
Former Digital Trends Contributor
Adam’s obsession with tech began at a young age, with a Sega Dreamcast – and he’s been hooked ever since. Previously…
The iPhone should copy this Android phone’s shortcut button feature, here’s why
The buttons on the iPhone 16e

The iPhone is renowned for its ability to start entire trends and drive the smartphone industry in new directions. 

Beginning with the launch of the original iPhone in 2007, which transitioned the industry from resistive to capacitive touchscreens and eliminated the need for a stylus, the iPhone also defined the current smartphone with the introduction of the App Store and the app economy.

Read more
My main computer is an M4 iPad Pro, but a 2021 iPad still surprises me
Rear shell of 2021 iPad Pro.

This might sound controversially ridiculous, but for the past few years, my primary computer has been an iPad Pro. I first got interested in pushing tablets this way when the M1 version came out, and I’ve kept using them all the way up to the newest M4-powered model. 

A few weeks ago, I went back to my M1 iPad Pro to see how well it handles next-gen apps that are pushing the boundaries of graphics and AI on a mobile device. So, the big question is whether the four-year-old slate can still serve as a reliable workhorse in 2025?

Read more
iPhone theft victim sues Apple. It sparks a new hope for others, too
The iPhone 16 sticking out of someone's pocket.

Smartphones are the center of our digital existence. Not just because they open the doors for communication and social connection, but also due to their role as gatekeepers of our financial and professional lives. 

Needless to say, a stolen iPhone can upend your life in many ways, but it’s even harder to recover those precious files stored on the device. A few victims of iPhone theft may finally have a chance, thanks to a lawsuit against Apple over not offering enough help in recovery efforts.

Read more