4 ms·
Indeed, however the notification also comes via iMessage and appears at the top of your Apple account, plus contains no external links
by internetter 1y ago
Indeed, however the notification also comes via iMessage and appears at the top of your Apple account, plus contains no external links
- aspenmayer 1y agoI wouldn’t be surprised if Apple’s malware notification comes via the same or similar mechanism as Apple 2FA codes on iOS, as iMessage itself is a common vector for these kinds of malware being warned of, such as Pegasus. Apple also notifies you of this kind of malware via the email used for your AppleID, in addition to on-device, though I wouldn’t be surprised if that same malware would attempt to monitor for these messages from Apple to prevent them from being received and/or read. The Apple Support app, for example, has capabilities which when triggered from the Apple side, allow screen-sharing and logging to be shared with Apple. I don’t know if this functionality relies on iMessage being enabled either, but I do know that the Apple Support app seemingly still works in Lockdown Mode. I’d be curious if the person in TFA had their device in Lockdown Mode, which supposedly is supposed to make these kinds of exploits harder to install. If they were using Lockdown Mode, and they still got exploited, that isn’t great news for the rest of us, but the fact that Apple notified them is better than the alternative of Apple not being aware of the breach and/or Apple being aware and not notifying them for reasons.