5 ms·
For backed up data to carry a piece of malware, they'd have to exploit a zero-day bug in iOS or in the associated app. That's possible in theory, but those have
by thinkling 8y ago
For backed up data to carry a piece of malware, they'd have to exploit a zero-day bug in iOS or in the associated app. That's possible in theory, but those have been rare, and once iOS or the app gets fixed, the exploit in the data is neutralized.
Looking at a list of known iOS malware [1] I don't offhand see any tools that manage to install themselves through exploits in non-jailbroken iOS or exploits normal App Store apps.
The closest thing I saw was an injection of malware into a pirated version of the Xcode developer tools, causing all apps compiled with that version to be infected. Those apps were then spread through a third-party app store--so again only loaded onto jailbroken iPhones.
Perhaps the scariest thing is something like Wirelurker[2] that spreads over USB connections and can spread from iPhones to Macs and back to other iPhones. People don't plug into other Macs very much, but if this were modified to affect CarPlay, it could spread from iPhone to rental car to iPhone, to iPhone, to iPhone...
[1] https://www.theiphonewiki.com/wiki/Malware_for_iOS https://www.theiphonewiki.com/wiki/Malware_for_iOS
[2] http://time.com/3560875/iphone-malware-wirelurker/ http://time.com/3560875/iphone-malware-wirelurker/
- graeme 8y agoGreat summary, thanks! So basically, exploits are possible on extremely high value targets like the president, but apart from that there are basically no malware worried for updated, non-jailbroken iphones. I'd been curious about this since reading about NSO Pegasus and their SMS method. Is this likely in the "zero day, high value target category"? I've never properly seen an explanation of how it's supposed to work. https://thehackernews.com/2018/07/iphone-hacking-spyware.html?m=1 https://thehackernews.com/2018/07/iphone-hacking-spyware.htm...