Google Project Zero Researchers Disclose 5 ‘Zero Interaction’ iMessage Flaws, 4 Fixed in iOS 12.4

One of the flaws can allow an attacker to read contents of files on iPhone.

Advertisement
By Gadgets 360 Staff | Updated: 30 July 2019 18:53 IST
Highlights
  • CVE-2019-8660 is a memory corruption flaw
  • Two of the disclosed flaws can lead to the crash of iPhone GUI
  • One of the researchers will detail the flaws at Black Hat USA 2019

CVE-2019-8641 vulnerability remains unpatched for now

Google Project Zero team has yet again found a number of security vulnerabilities in Apple's iOS operating system. Two members of the Project Zero team discovered five new “zero interaction” flaws in iMessage that could allow an attacker to all sorts of malicious things on an iPhone, ranging from crashing an app to reading contents of a file. Apple has fixed five of the disclosed vulnerabilities, but one flaw remains unpatched right now.

According to a series of tweets published by Google Project Zero's Natalie Silvanovich, the researcher with Samuel Grob found five vulnerabilities in Apple's iMessage. These vulnerabilities are being called zero interaction as they don't require the user to do anything apart from opening a malicious iMessage. As Apple has already fixed four of these vulnerabilities in the recently released iOS 12.4 - CVE-2019-8647, CVE-2019-8624, CVE-2019-8646, and CVE-2019-8660 – their details are now public. However, CVE-2019-8641 is still unpatched, so the researchers are keeping its details secret until 90 days disclosure deadline.

Advertisement

The biggest of the newly disclosed flaws is CVE-2019-8646 and it impacts devices running iOS 12 and above. The flaw allows potential attackers to read contents of files stored on an iOS device without any user interaction.

Among other iMessage flaws, CVE-2019-8660 is a memory corruption flaw and CVE-2019-8624 as well as CVE-2019-8647 can cause crash of iOS SpringBoard, which manages the iOS graphical user interface (GUI).

Advertisement

In addition to these flaws, Natalie Silvanovich was also responsible for finding CVE-2019-8662, which is although not directly released to iMessage, but can be triggered though the messaging app.

Natalie Silvanovich will be talking more about the bugs at the upcoming Black Hat USA 2019 conference.

Advertisement

To recall, Apple had released iOS 12.4 for the iPhone, iPad, and iPod Touch users. In addition to a number of bug fixes, the update included a new feature to transfer data wirelessly between two iPhone models and enhancements for Apple News+.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. How to Watch Jensen Huang's Keynote at the Nvidia GTC 2026
  2. NASA's Dragonfly Moves Into the Assembly Phase to Uncover Titan's Mysteries
  1. NASA Begins Building Dragonfly Drone; Nuclear-Powered ‘Octocopter’ Enters Testing Ahead of 2028 Launch
  2. Kenatha Kanom Locks OTT Platform: When and Where to Watch Yogi Babu’s Rural Satire Online?
  3. Local Times OTT Release Date: What to Know About This New Malayalam Friendship Comedy
  4. Muthu Alias Kattan OTT Release Date: When and Where to Watch Vijay Sethupathi Starrer Online?
  5. Funky Available for Streaming Online: Where to Watch Vishwak Sen’s New Comedy Directed by Anudeep KV?
  6. Border 2 OTT Release Date: When and Where to Watch Sunny Deol and Varun Dhawan Starrer Online?
  7. Nvidia GTC 2026: How to Watch Jensen Huang’s Nvidia keynote and What to Expect
  8. Scientists Trace Rare Cosmic Outburst to a Massive Planetary Collision Around Gaia20ehk
  9. That Night Streaming on Netflix: What to Know About Clara Galle and Claudia Salas Starrer
  10. Jazz City OTT Release Date: When and Where to Watch Arifin Shuvoo and Sauraseni Maitra Starrer Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.