Researchers: Apple and Google should provide more access to iOS and Android system internals to help catch more attacks by Pegasus-like spyware in real time
Amnesty International sheds alarming light on an NSO Group surveillance tool—and the gaps in Apple and Google's defenses.
Context & Ripple Effects
Amnesty International had just released an iPhone and Android compromise-scanning toolkit, while earlier research documented iOS and Android weaknesses that can expose user data. The new call shifts the focus from finding evidence after a suspected compromise to whether the platform owners expose enough system-level telemetry for detection during an attack.
The concern also follows a longer record of NSO-linked iPhone exploitation, including zero-day flaws Apple patched after attacks on activists. Related coverage argues that Apple and Google can alter the economics of NSO-style exploitation, making platform-level visibility a practical part of the defense debate.
First-order effects
- Apple and Google face a concrete request to expand researchers' access to iOS and Android internals, so spyware detection can move beyond the evidence available to external scanning tools.
- Amnesty International and other investigators would have a stronger basis for identifying Pegasus-like infections in real time if the requested access is provided.
Second-order effects
- NSO Group's surveillance tooling faces higher operating risk if Apple and Google use greater system visibility to identify attacks faster, reinforcing the related argument that platforms can raise the cost of mass exploitation.
- Security research groups become more dependent on platform-controlled diagnostic access, concentrating a larger share of mobile incident detection in Apple and Google's operating-system policies.
Third-order effects
- Mobile-platform observability is becoming a security boundary: the degree of access Apple and Google grant outside researchers will shape whether independent spyware detection can keep pace with highly privileged attacks.
- If platform owners pair internal detection with target outreach, the model moves from forensic discovery toward vendor-led victim notification, as reflected in Apple's later commitment to notify targets of state-sponsored spyware.
The trend: Commercial spyware is pushing mobile security from post-compromise forensic tooling toward platform-mediated, real-time detection and notification.