/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An in-depth look at five iOS exploit chains that were used in hacked websites for carrying out watering hole attacks against devices running iOS 10 through 12

Project Zero's mission is to make 0-day hard.  We often work with other companies to find and report security vulnerabilities …

Project Zero Ian Beer

Context & Ripple Effects

This analysis closes the loop opened in July, when Google Project Zero [[a:944339|published details and demo exploit code for five of six "interactionless" iOS security bugs]] — bugs that required no user tap to trigger, and which iOS 12.4 patched all but one of. What was then a research disclosure has turned out to be a description of live infrastructure: hacked websites were serving these exact chains as watering hole attacks against visitors running iOS 10 through 12.

The significance is attribution-adjacent rather than academic. Project Zero's own follow-on reporting later tied seven additional zero-days targeting iOS, Windows, and Android to the same hacking operation, making this writeup the earliest documented snapshot of an actor running sustained, cross-platform zero-day campaigns.

First-order effects

  • Visitors on unpatched iOS 10–12 devices who landed on compromised websites could be fully compromised without any interaction — browsing itself was the attack surface.
  • Apple faced immediate pressure to close the full set: the July disclosure showed five of six interactionless bugs already fixed in iOS 12.4, leaving exactly the kind of residual gap watering hole operators exploit.

Second-order effects

  • Publishing demo-quality exploit code while the bugs are still being used in the wild sharpens the debate over disclosure timing — defenders get detection signatures, but so do other operators before every user upgrades off iOS 12.
  • The documented chain structure pushes platform vendors toward hardening the browser sandbox and reducing the value of any single webkit-level bug, since each chain here stacked multiple bugs to escape it.

Third-order effects

  • The pattern points toward interactionless, browser-delivered compromise as the default model for high-end mobile attacks — reinforced two years later by the zero-click AWDL protocol exploit that needed no website visit at all.
  • If one operation can sustain zero-day pipelines across iOS, Windows, and Android simultaneously, defense economics shift from per-vendor patching toward shared indicators and coordinated industry response.

The trend: Mobile exploitation is consolidating around interactionless, chain-based attacks delivered through ordinary browsing, forcing vendors to treat silent remote compromise as the baseline threat model.

Discussion

  • @cramforce Malte Ubl on x
    If Apple allowed browser engine diversity on iOS, then fewer than 100% of iOS users would have been vulnerable over this 2 year period https://www.washingtonpost.com/ ...
  • @stshank Stephen Shankland on x
    A dig from a Googler about Apple's ostensibly security-minded (in part) reason for allowing only its own browser engine on iOS & iPadOS. (Chrome, Firefox, etc. are available on iOS, but unlike on MacOS, Windows, Android, are required to use Apple's WebKit browser engine.) https:/…
  • @alexstamos Alex Stamos on x
    It's darkly ironic that Apple is the company that is demonstrating the end point of late-90's fears about Microsoft. ✅Rent seeking via platform control. ✅Content moderation on behalf of autocracies ✅Risk of software monoculture[1] [1] http://blough.ece.gatech.edu/ ...
  • @alexstamos Alex Stamos on x
    Many things to learn from this incident, but one is the safety cost of anti-competitive iOS App Store policies. Chrome/Brave/Firefox are required to use the default WebKit/JS. If Apple isn't going to put in the work necessary to protect users then they should let others do so. ht…
  • @reneritchie Rene Ritchie on x
    Terrific drill-down on a web-based iOS exploit chain. But, I can't find any info on what kind of sites were being used? If they were a tiny cluster in a remote region vs. major multinational, it's a very different threat level. https://googleprojectzero.blogspot.com/ ...
  • @alexhern Alex Hern on x
    As this has filtered from the security community to the mainstream, something's been lost in translation, so I want to be explicit: this is not an aggressive move by Google, and it's not part of the wider conflict between the two companies. https://www.theguardian.com/ ...
  • @ericgeller Eric Geller on x
    HUGE mobile security news: Google found malicious websites indiscriminately hacking iPhones using at least 5 separate exploit chains w/ *14* individual 0days. https://googleprojectzero.blogspot.com/ ... This is like finding a live colossal squid at the beach. Just *one* iOS 0day …
  • @martijn_grooten Martijn Grooten on x
    There's a lot to say about the iPhone watering hole attacks, but if you work with vulnerable groups in China this, and the fact that P0 talked about “entire populations”, means should you take extra notice of what happened https://googleprojectzero.blogspot.com/ ... https://googl…
  • @alexstamos Alex Stamos on x
    This is a huge find by Google's team. Attribution for these sites is going to be critical to understanding what impact they might have had. https://twitter.com/...
  • @malwarejake Jake Williams on x
    This, plus a hardcoded HTTP IP address is amateur hour. Contrast that with multiple exploit chains and sandbox escapes and it sure sounds like a group with tons of money to buy exploits and little operational experience. So many thoughts right now... https://googleprojectzero.blo…
  • @malwaretechblog @malwaretechblog on x
    This is wild. A group were using hacked websites to indiscriminately exploit iPhones using zero days exploits, and somehow went unnoticed for years. https://googleprojectzero.blogspot.com/ ...
  • @savicali Savic Ali on x
    Privacy is an illusion in digital world. https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    Google's Threat Analysis Group found hacked sites being used in watering hole attacks using five distinct iPhone 0-day exploit chains. The websites had thousands of visitors per week. Project Zero's analysis starts here: https://googleprojectzero.blogspot.com/ ...
  • @_danielsinclair Daniel Sinclair on x
    Wow. This Project Zero discovery is insane. Some unnamed entity (obviously a government) had 7 Safari 0-days that have been quietly compromising iPhones for years — all the way back to iOS 10. Anyone who visited these unnamed sites were sunk. https://googleprojectzero.blogspot.co…
  • @da_667 @da_667 on x
    the iOS 0-day/implant that google TAG found just really goes to show you why there is such a big market for iOS 0-days. With the right exposure, its intelligence goldmine that reaps massive dividends.
  • @lukolejnik Lukasz Olejnik on x
    The implant was used to steal location data and files like databases of WhatsApp, Telegram, iMessage. So all the user messages, or emails. Copies of contacts, photos, https://googleprojectzero.blogspot.com/ ... https://twitter.com/...
  • @motherboard @motherboard on x
    Thousands of iPhones per week have been indiscriminately hacked for YEARS and no one knew: https://www.vice.com/...
  • @craiu Costin Raiu on x
    So, people with access to big chunks of network traffic should probably scout for HTTP POSTs to “/list/suc?name=”. https://googleprojectzero.blogspot.com/ ...
  • @cynicalsecurity Arrigo Triulzi on x
    All I am going to say about the iOS exploit chains write up by Project Zero is: “Bloody Hell!”. In the most profound British understatement tone I can muster. https://googleprojectzero.blogspot.com/ ...
  • @jason_koebler Jason Koebler on x
    this is crazy crazy crazy crazy crazy. Upends everything I thought I knew about iPhone security. https://www.vice.com/...
  • @kennethgeers Kenneth Geers on x
    Strategic iOS Attack —> “rare and intricate chains of code exploited a total of 14 security flaws” https://www.wired.com/...
  • @lilyhnewman Lily Hay Newman on x
    not to be _dramatic_ but this actually does change everything https://www.wired.com/...
  • @robpegoraro Rob Pegoraro on x
    As you read this, don't forget how often various government types have complained that our mobile devices are now too secure for them to investigate crimes. https://twitter.com/...
  • @zittrain Jonathan Zittrain on x
    Apple iOS has been considered the most secure smartphone OS. Disconcerting that flaws could be strung together not only to own the phone, but to do it in bulk for all users visiting a compromised/ing web site. https://twitter.com/... https://twitter.com/...