Apple Issues iOS 14.8 to Fix a Flaw Linked to Pegasus Spyware

Apple said it had "rapidly" developed the update following Citizen Lab's discovery of the problem.

Advertisement
By Agence France-Presse | Updated: 14 September 2021 09:55 IST
Highlights
  • NSO did not dispute Pegasus had prompted the urgent software upgrade
  • Pegasus has evolved to become more effective since it was uncovered
  • Pegasus can switch on a phone's camera or microphone

Researchers at Citizen Lab found the problem with iPhone while analysing a Saudi activist's phone

Apple released iOS 14.8 to fix a weakness that can let the spyware at the heart of the Pegasus scandal infect devices without users even clicking on a malicious message or link.

The Pegasus software from Israeli firm NSO Group has been under intense scrutiny since an international media investigation claimed it was used to spy on the phones of human rights activists, journalists, and even heads of state.

Advertisement

Researchers at Citizen Lab, a cybersecurity watchdog organisation in Canada, found the problem while analysing a Saudi activist's phone that had been compromised with the code.

"We determined that the mercenary spyware company NSO Group used the vulnerability to remotely exploit and infect the latest Apple devices with the Pegasus spyware," Citizen Lab wrote in a post.

In March Citizen Lab examined the activist's phone and determined it was hacked with Pegasus spyware introduced via iMessage texting and that it didn't even require the phone's user to so much as click.

Advertisement

Hours after releasing the fix, Apple said it had "rapidly" developed the update following Citizen Lab's discovery of the problem.

"Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals," the company said.

Advertisement

NSO did not dispute Pegasus had prompted the urgent software upgrade, and said in a statement that it would "continue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime."

No click needed

Pegasus has evolved to become more effective since it was uncovered by Citizen Lab and cyber security firm Lookout five years ago.

Advertisement

Pegasus can be deployed as a "zero-click exploit," meaning that the spyware can install itself without the victim even clicking a booby-trapped link or file, according to Lookout senior manager Hank Schless.

"Many apps will automatically create a preview or cache of links in order to improve the user experience," Schless said.

"Pegasus takes advantage of this functionality to silently infect the device."

UN experts recently called for an international moratorium on the sale of surveillance technology until regulations are implemented to protect human rights following an Israeli spyware scandal.

An international media investigation reported in July that several governments used the Pegasus malware, created by NSO Group, to spy on activists, journalists, and politicians. 

Pegasus can switch on a phone's camera or microphone and harvest its data.

"It is highly dangerous and irresponsible to allow the surveillance technology and trade sector to operate as a human rights-free zone," the United Nations human rights experts said in a statement at the time.

The statement was signed by three special rapporteurs on rights and a working group on the issue of human rights and transnational corporations and other businesses.

Israel's defense establishment has set up a committee to review NSO's business, including the process through which export licences are granted.

NSO insists its software is intended for use only in fighting terrorism and other crimes, and says it exports to 45 countries.


This week on Orbital, the Gadgets 360 podcast, we discuss iPhone 13 leaks and what we expect from the Apple event. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, iOS, NSO Group, Pegasus, spyware
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the B by Lenskart Smart Glasses Will Cost in India
  2. One UI 9 Leak Shows the Design of the Samsung Galaxy Z Fold 8, Z Wide Fold
  3. Top Phones Under Rs. 50,000 in India: iQOO 15R Takes the Lead
  4. OnePlus Summer Sale: Deals on OnePlus 15, OnePlus 13 and More Announced
  5. Samsung Galaxy S27 Ultra Might Reintroduce This Useful Camera Feature
  6. Detailed Google Pixel 11 Series Leak Reveals Chip, Cameras and Design
  7. Xiaomi India Claims Record Performance in Mid-Premium Smartphone Segment
  1. Google to Host The Android Show Ahead of I/O 2026 Developer Conference Next Week
  2. Astronomers Use Webb Telescope to Study Exoplanet Surface Beyond Atmosphere
  3. Temple Wearable Enters Early Access: Zomato Co-Founder Deepinder Goyal Says First 100 Units Ready to Ship
  4. Samsung Galaxy A27 Seemingly Confirmed via Company's Website, Could Launch Soon
  5. Western Union Launches USDPT Stablecoin on Solana Blockchain, Coin Issued by Anchorage Digital
  6. Anthropic Announces New AI Services Company, OpenAI Reportedly Follows Suit
  7. Samsung Galaxy Z Fold 8, Galaxy Z Wide Fold Design Emerges via One UI 9 Leak
  8. Honor Play 80 Plus Launched With 7,500mAh Battery, 13-Megapixel Camera: Price, Specifications
  9. Kuheli OTT Release Date: When and Where to Watch This Bengali Murder Mystery Online?
  10. Thukra Ke Mera Pyaar Season 2 OTT Release Date: When and Where to Watch it Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.