Johns Hopkins researchers find an iMessage bug that allows attackers to decrypt photos and videos on older iOS versions
Johns Hopkins researchers poke a hole in Apple's encryption — Apple's growing arsenal of encryption techniques — shielding data on devices as well as real …
Context & Ripple Effects
This is academic cryptanalysis hitting Apple's messaging stack at its most sensitive point: Johns Hopkins researchers showed that on older iOS versions an attacker could decrypt photos and videos sent over iMessage, undercutting the end-to-end encryption promise Apple was marketing at the time. The disclosure moved fast — Apple shipped a mitigation in iOS 9.3 built along lines the researchers proposed, within roughly a day of publication.
The episode matters less as a one-off bug than as the opening entry in a pattern the related coverage traces forward: iMessage kept resurfacing as the attack surface of choice, from the NSO-linked zero-days used against activists later in 2016 to the multi-year zero-click campaign detailed in 2023.
First-order effects
- Users who had not updated past older iOS versions had their iMessage photo and video attachments exposed to decryption by anyone exploiting the flaw — the fix only reached them through the iOS 9.3 update.
- Apple absorbed a public crack in its flagship encryption story and responded immediately, shipping the Johns Hopkins-proposed mitigation in iOS 9.3 rather than waiting for a normal release cycle.
Second-order effects
- The demonstration validated iMessage as a high-value target for attackers with resources: months later, zero-day iOS flaws likely sold by malware vendor NSO were used in attempts to remotely steal data from activists, forcing another out-of-band patch in iOS 9.3.5.
- Each rapid patch cycle raised the stakes for users on old devices, since unpatched iPhones became the reliable population for every subsequent iMessage exploit chain.
Third-order effects
- If the pattern holds, iMessage becomes the structural front door for commercial spyware against iPhones — pushing Apple toward ever-faster emergency patching and hardened message handling, while researchers note the flip side: iOS security controls now make it genuinely hard to verify whether a given iPhone has been compromised without jailbreaking it first.
The trend: iMessage has shifted from an academic cryptography target into the primary delivery vector for commercial spyware, with Apple's emergency-patch cadence becoming the de facto defense.