An in-depth look at five iOS exploit chains that were used in hacked websites for carrying out watering hole attacks against devices running iOS 10 through 12
Project Zero's mission is to make 0-day hard. We often work with other companies to find and report security vulnerabilities …
Project Zero Ian Beer
Context & Ripple Effects
This analysis closes the loop opened in July, when Google Project Zero [[a:944339|published details and demo exploit code for five of six "interactionless" iOS security bugs]] — bugs that required no user tap to trigger, and which iOS 12.4 patched all but one of. What was then a research disclosure has turned out to be a description of live infrastructure: hacked websites were serving these exact chains as watering hole attacks against visitors running iOS 10 through 12.
The significance is attribution-adjacent rather than academic. Project Zero's own follow-on reporting later tied seven additional zero-days targeting iOS, Windows, and Android to the same hacking operation, making this writeup the earliest documented snapshot of an actor running sustained, cross-platform zero-day campaigns.
First-order effects
- Visitors on unpatched iOS 10–12 devices who landed on compromised websites could be fully compromised without any interaction — browsing itself was the attack surface.
- Apple faced immediate pressure to close the full set: the July disclosure showed five of six interactionless bugs already fixed in iOS 12.4, leaving exactly the kind of residual gap watering hole operators exploit.
Second-order effects
- Publishing demo-quality exploit code while the bugs are still being used in the wild sharpens the debate over disclosure timing — defenders get detection signatures, but so do other operators before every user upgrades off iOS 12.
- The documented chain structure pushes platform vendors toward hardening the browser sandbox and reducing the value of any single webkit-level bug, since each chain here stacked multiple bugs to escape it.
Third-order effects
- The pattern points toward interactionless, browser-delivered compromise as the default model for high-end mobile attacks — reinforced two years later by the zero-click AWDL protocol exploit that needed no website visit at all.
- If one operation can sustain zero-day pipelines across iOS, Windows, and Android simultaneously, defense economics shift from per-vendor patching toward shared indicators and coordinated industry response.
The trend: Mobile exploitation is consolidating around interactionless, chain-based attacks delivered through ordinary browsing, forcing vendors to treat silent remote compromise as the baseline threat model.
Related: Dual-use code intelligence · Google Project Zero publishes interactionless iOS bug details · Same hackers' later zero-day campaigns · Zero-click AWDL iOS exploit
Related Coverage
- Google Says Malicious Websites Have Been Quietly Hacking iPhones for Years VICE · Joseph Cox
- Implant Teardown — In the earlier posts we examined … Project Zero
- Google says hackers have put ‘monitoring implants’ in iPhones for years The Guardian · Alex Hern
- Websites have been quietly hacking iPhones for years, says Google MIT Technology Review · Patrick Howell O'Neill
- iPhone Zero-Days Anchored Watering-Hole Attacks Threatpost · Tara Seals
- Report: Websites hacked iPhones for years Axios · Joe Uchill
- Malicious websites were used to secretly hack into iPhones for years, says Google TechCrunch · Zack Whittaker
- Google Outlines iPhone Vulnerabilities That Let Malicious Websites Steal User Data for Years, Now Fixed MacRumors · Mitchel Broussard
- WhatsApp Security Destroyed By Just Visiting A Website—Why The Latest iPhone Hack Is Terrifying Forbes · Thomas Brewster
- Google's Project Zero details ‘indiscriminate’ hacking campaign against thousands of iPhones CyberScoop · Jeff Stone
- Google's Elite Hacking Team Reveals Untimely Bug in iPhone Bloomberg · Allison Ingersoll
- Google uncovers collection of malicious sites that secretly hacked iPhones iMore · Babu Mohan
- Google discovers major iPhone security flaw that affected thousands NBC News · Todd Haselton
- Google finds evidence of attempted mass iPhone hack CNN · Rishi Iyengar
- Google finds ‘indiscriminate iPhone attack lasting years’ BBC · Dave Lee
- Google uncovers evidence of large iPhone hacking attempt The Hill · Maggie Miller
- Google says a bunch of malicious websites have been secretly hacking iPhones for years KnowTechie · Joe Rice-Jones
- Malicious websites have been quietly hacking iPhones for the past couple of years Firstpost Tech
- iOS Vulnerabilities Allowed Attackers to Remotely Hack iPhones for Years SecurityWeek · Ionut Arghire
- Sophisticated iPhone hacking went unnoticed for over two years Naked Security · John E Dunn
- Latest iOS Hack is a Game Changer The Mac Observer · Charlotte Henry
- iPhone exploit active “at least two years” detailed by Google SlashGear · Chris Davies
- Google says hacked websites were attacking iPhones for years TechSpot · Rob Thubron
- Google lays out iOS malware exploits found in the wild, but already patched by Apple back in February The Loop · Dave Mark
- Hackers used malicious websites to hack iPhones: Passwords, photos, chats, live location exposed International Business Times · Sami Khan
- How to protect yourself against the latest big iPhone security scare Apple Must · Jonny Evans
- Google warns about two iOS zero-days ‘exploited in the wild’ ZDNet · Catalin Cimpanu
- Google says iPhone security holes went unnoticed for 2 years Cult of Mac · David Pierini
- Google discovered ‘sustained attacks’ over at least two years against iPhone users Neowin · Jay Bonggolto
- Google unearths 2-year-long iPhone spyware attack Financial Times · Tim Bradshaw
- iPhone exploits in hacked websites went unnoticed for years AppleInsider · Mikey Campbell
- Google discovered websites that could hack your iPhone just by visiting them Fast Company · Michael Grothaus
- Google Finds Massive iPhone Vulnerability that Was Exploited for Years Softpedia News · Silviu Stahie
- Google has discovered malicious websites targeting iPhone users Gizchina · Abdullah
- Google reveals major iPhone security flaws that let websites hack phones The Verge · Jon Porter
- Massive iPhone Hack Uncovered by Google: What You Need to Know Tom's Guide · Richard Priday
- Google finds malicious sites pushing iOS exploits for years ZDNet · Catalin Cimpanu
- Google uncovers exploit-laden websites that stole data from iPhones Engadget · Mariella Moon
- Google Uncovers How Just Visiting Some Sites Were Secretly Hacking iPhones For Years The Hacker News · Swati Khandelwal
- Google says iPhone security flaws let websites hack away for years CNET · Alfred Ng
- Google researchers reveal data-stealing, web-based iPhone exploit that was active for years The Next Web · Ravie Lakshmanan
- Google exposes massive iPhone hacking operation Telecoms.com · Scott Bicheno
- Thousands of Fully Patched iPhones Exploited for Years, says Google - Who Is the Sophisticated Mystery Attacker? Computer Business Review · Ed Targett
- Google says older iPhones have a security flaw. Here's how to protect yourself Digital Trends · Mark Jansen
- Google security researcher warns that hackers are using malicious websites to exploit iOS flaws and monitor iPhone users BetaNews · Mark Wyciślik-Wilson
- Google researchers found a bunch of malicious sites that quietly hacked iPhones for years Business Insider · Isobel Asher Hamilton
- Google researchers found an iOS security hole was left open for years Pocket-lint · Dan Grabham
- Google researchers found mass iPhone hack attempt Seeking Alpha · Brandy Betz
- Google's Project Zero Team Details Malicious Websites That Hacked iPhones for Years iPhone Hacks · Rajesh Pandey
- Hacked sites attacked thousands of iPhones every week for years using undiscovered exploits Mashable · Caitlin Welsh
- These malicious website exploits targeted iPhone users for years MacDailyNews
- Here's Why You Should Update to iOS 12.1.4 Right Now (It's Not the Spy Bug) iDrop News · Mike Peterson
- Google researcher says iOS 12.1.4 fixes two zero-day vulnerabilities that ‘were exploited in the wild’ 9to5Mac · Chance Miller
- What You Need to Know About the iPhone Malware News Slate · Josephine Wolff
- Google researchers detail malicious website exploits that targeted iPhone users for years 9to5Mac · Chance Miller
- Malicious Websites Have Been Hacking iPhones The Mac Observer · Andrew Orr
- Update your iPhone's operating system as soon as possible Quartz · Mike Murphy
- Google's Project Zero team uncovers ‘sustained’ hack on Apple iOS devices Inquirer · Chris Merriman
Discussion
-
@cramforce
Malte Ubl
on x
If Apple allowed browser engine diversity on iOS, then fewer than 100% of iOS users would have been vulnerable over this 2 year period https://www.washingtonpost.com/ ...
-
@stshank
Stephen Shankland
on x
A dig from a Googler about Apple's ostensibly security-minded (in part) reason for allowing only its own browser engine on iOS & iPadOS. (Chrome, Firefox, etc. are available on iOS, but unlike on MacOS, Windows, Android, are required to use Apple's WebKit browser engine.) https:/…
-
@alexstamos
Alex Stamos
on x
It's darkly ironic that Apple is the company that is demonstrating the end point of late-90's fears about Microsoft. ✅Rent seeking via platform control. ✅Content moderation on behalf of autocracies ✅Risk of software monoculture[1] [1] http://blough.ece.gatech.edu/ ...
-
@alexstamos
Alex Stamos
on x
Many things to learn from this incident, but one is the safety cost of anti-competitive iOS App Store policies. Chrome/Brave/Firefox are required to use the default WebKit/JS. If Apple isn't going to put in the work necessary to protect users then they should let others do so. ht…
-
@reneritchie
Rene Ritchie
on x
Terrific drill-down on a web-based iOS exploit chain. But, I can't find any info on what kind of sites were being used? If they were a tiny cluster in a remote region vs. major multinational, it's a very different threat level. https://googleprojectzero.blogspot.com/ ...
-
@alexhern
Alex Hern
on x
As this has filtered from the security community to the mainstream, something's been lost in translation, so I want to be explicit: this is not an aggressive move by Google, and it's not part of the wider conflict between the two companies. https://www.theguardian.com/ ...
-
@ericgeller
Eric Geller
on x
HUGE mobile security news: Google found malicious websites indiscriminately hacking iPhones using at least 5 separate exploit chains w/ *14* individual 0days. https://googleprojectzero.blogspot.com/ ... This is like finding a live colossal squid at the beach. Just *one* iOS 0day …
-
@martijn_grooten
Martijn Grooten
on x
There's a lot to say about the iPhone watering hole attacks, but if you work with vulnerable groups in China this, and the fact that P0 talked about “entire populations”, means should you take extra notice of what happened https://googleprojectzero.blogspot.com/ ... https://googl…
-
@alexstamos
Alex Stamos
on x
This is a huge find by Google's team. Attribution for these sites is going to be critical to understanding what impact they might have had. https://twitter.com/...
-
@malwarejake
Jake Williams
on x
This, plus a hardcoded HTTP IP address is amateur hour. Contrast that with multiple exploit chains and sandbox escapes and it sure sounds like a group with tons of money to buy exploits and little operational experience. So many thoughts right now... https://googleprojectzero.blo…
-
@malwaretechblog
@malwaretechblog
on x
This is wild. A group were using hacked websites to indiscriminately exploit iPhones using zero days exploits, and somehow went unnoticed for years. https://googleprojectzero.blogspot.com/ ...
-
@savicali
Savic Ali
on x
Privacy is an illusion in digital world. https://twitter.com/...
-
@howelloneill
Patrick Howell O'Neill
on x
Google's Threat Analysis Group found hacked sites being used in watering hole attacks using five distinct iPhone 0-day exploit chains. The websites had thousands of visitors per week. Project Zero's analysis starts here: https://googleprojectzero.blogspot.com/ ...
-
@_danielsinclair
Daniel Sinclair
on x
Wow. This Project Zero discovery is insane. Some unnamed entity (obviously a government) had 7 Safari 0-days that have been quietly compromising iPhones for years — all the way back to iOS 10. Anyone who visited these unnamed sites were sunk. https://googleprojectzero.blogspot.co…
-
@da_667
@da_667
on x
the iOS 0-day/implant that google TAG found just really goes to show you why there is such a big market for iOS 0-days. With the right exposure, its intelligence goldmine that reaps massive dividends.
-
@lukolejnik
Lukasz Olejnik
on x
The implant was used to steal location data and files like databases of WhatsApp, Telegram, iMessage. So all the user messages, or emails. Copies of contacts, photos, https://googleprojectzero.blogspot.com/ ... https://twitter.com/...
-
@motherboard
@motherboard
on x
Thousands of iPhones per week have been indiscriminately hacked for YEARS and no one knew: https://www.vice.com/...
-
@craiu
Costin Raiu
on x
So, people with access to big chunks of network traffic should probably scout for HTTP POSTs to “/list/suc?name=”. https://googleprojectzero.blogspot.com/ ...
-
@cynicalsecurity
Arrigo Triulzi
on x
All I am going to say about the iOS exploit chains write up by Project Zero is: “Bloody Hell!”. In the most profound British understatement tone I can muster. https://googleprojectzero.blogspot.com/ ...
-
@jason_koebler
Jason Koebler
on x
this is crazy crazy crazy crazy crazy. Upends everything I thought I knew about iPhone security. https://www.vice.com/...
-
@kennethgeers
Kenneth Geers
on x
Strategic iOS Attack —> “rare and intricate chains of code exploited a total of 14 security flaws” https://www.wired.com/...
-
@lilyhnewman
Lily Hay Newman
on x
not to be _dramatic_ but this actually does change everything https://www.wired.com/...
-
@robpegoraro
Rob Pegoraro
on x
As you read this, don't forget how often various government types have complained that our mobile devices are now too secure for them to investigate crimes. https://twitter.com/...
-
@zittrain
Jonathan Zittrain
on x
Apple iOS has been considered the most secure smartphone OS. Disconcerting that flaws could be strung together not only to own the phone, but to do it in bulk for all users visiting a compromised/ing web site. https://twitter.com/... https://twitter.com/...