Skip to main content
  1. Home
  2. Phones
  3. Apple
  4. Computing
  5. Mobile
  6. News

Update your iOS device to 9.3.5 as it fixes serious security vulnerabilities

Got a notification to update your iOS device to 9.3.5? You really shouldn’t wait to install it — the new version fixes three security vulnerabilities that were actively exploited by an Israel-based company in an episode likely involving the UAE government and a spy operation.

The NSO Group sells surveillance software that utilizes three zero-day vulnerabilities in iOS — it’s something that rarely happens in the wild, according to the team of researchers that reported the flaws to Apple. “Zero days” means the flaws were previously unknown, and a company had no time, or “zero days,” to fix them.

Recommended Videos

It all started with Ahmed Mansoor, a well-recognized human rights defender based in the United Arab Emirates. On August 10 and 11, Mansoor got an SMS on his iPhone “promising “new secrets” about detainees tortured in UAE jails if he clicked on an included link.

Mansoor didn’t click the link — he sent it straight to Citizen Lab researchers housed in the University of Toronto. If Mansoor had followed the link, the exploit would have remotely jailbroken his iPhone 6, and installed spyware.

“Once infected, Mansoor’s phone would have become a digital spy in his pocket, capable of employing his iPhone’s camera and microphone to snoop on activity in the vicinity of the device, recording his WhatsApp and Viber calls, logging messages sent in mobile chat apps, and tracking his movements,” according to Citizen Labs’ report.

The team worked with researchers at Lookout Security and managed to track the exploit back to NSO Group, a “cyber-war” company that sells Pegasus, a government-exclusive “lawful intercept” spyware product. Oddly, NSO Group is owned by an American venture capital firm named Francisco Partners Management.

“The high cost of iPhone zero-days, the apparent use of NSO Group’s government-exclusive Pegasus product, and prior known targeting of Mansoor by the UAE government provide indicators that point to the UAE government as the likely operator behind the targeting,” the researchers write in the report.

Immediately after discovering Trident, Citizen Labs and Lookout Security notified Apple. The Cupertino company said it would address the vulnerabilities — and 10 days later, Apple patched them up in iOS 9.3.5. It’s likely the last update to iOS 9, as iOS 10 is likely to release soon.  

The exploit and patch come weeks after Apple announced its first bug bounty program, which is to begin as an invitation-only process with the company doling out rewards as high as $200,000 for discovered vulnerabilities.

The update is available to all devices running iOS 9 through an over-the-air update.

Julian Chokkattu
Former Mobile and Wearables Editor
Julian is the mobile and wearables editor at Digital Trends, covering smartphones, fitness trackers, smartwatches, and more…
Android could soon let you lock out users from Wi-Fi networks on shared devices
Android is finally giving users the power to decide who gets automatic access to saved networks on shared phones and tablets.
Android 16 logo on Google Pixel 6a held in hand.

Google is developing a new set of Wi-Fi controls for Android that will let users choose whether a saved Wi-Fi network is shared with other profiles on the same device (via Android Authority).

Currently, when a device connects to a Wi-Fi network, all other profiles on the device automatically gain access without any verification. However, a new "Share Network" toggle in the latest Android Canary build lets users turn it off, so only the profile that entered the credentials in the first place can connect automatically.

Read more
Apple’s next iPad mini could take a big leap in performance and visual experience
Apple's smallest tablet may be on track for its most significant leap yet, combining a next-generation A20 Pro chip with an OLED display.
Person holding the iPad Mini 7.

Apple's next iPad mini could be significantly more powerful than its predecessor, says a MacRumors report. The publication claims that the purported iPad mini could feature Apple's A20 Pro chip, and if you haven't heard its name yet, that's because it is supposed to launch alongside the iPhone 18 Pro models in 2026.

Not too long ago, rumors claimed that the eighth-generation iPad mini will feature the A19 Pro chip, the one powering the iPhone 17 Pro models. While that would also have provided a considerable performance boost over the A17 Pro chip in the current-generation iPad mini, the A20 Pro could be a monumental jump for the iPad mini, giving it enough headroom for several years.

Read more
Instacart may have charged you more for the same groceries and it’s just another case of AI hell
Instacart

A new investigation by Consumer Reports, in collaboration with Groundwork Collaborative and More Perfect Union, suggests that Instacart’s use of artificial intelligence in pricing experiments may have resulted in shoppers paying different amounts for the same groceries.

The findings point to a system where prices can quietly vary between users, even when orders are placed at the same retailer, at the same time, and for identical products. The study tracked over 400 Instacart users across four major U.S. cities and found that the price tag on a carton of eggs or a bag of chips often depended on who was holding the phone.

Read more