WhatsApp and Apple Address Critical Security Flaws Targeting iPhones and iPads
NEW YORK – WhatsApp, the widely used messaging application owned by Meta Platforms, has swiftly addressed a critical security vulnerability that facilitated sophisticated cyberattacks against the Apple devices of a limited number of high-value targets. The vulnerability, when combined with a specific bug found within Apple’s iOS and iPadOS operating systems, allowed hackers to illicitly access and steal sensitive information from affected devices.
Exploit Chain and Duration of Attack
The exploit chain enabled attackers to remotely compromise iPhones and iPads, potentially gaining access to private communications, contacts, and other confidential data. According to Donncha Ó Cearbhaill, a researcher at Amnesty’s Security Lab, this malicious campaign was active for approximately 90 days, indicating a sustained and deliberate effort by the perpetrators. Ó Cearbhaill also suggested that the underlying vulnerabilities might have extended their reach beyond WhatsApp, potentially impacting other applications.
WhatsApp’s Response and User Advisory
WhatsApp confirmed that fewer than 200 users were specifically targeted in these attacks. The company has since initiated contact with all identified victims to inform them of the compromise and advise them on protective measures. While WhatsApp has released a patch for its application, all users are strongly urged to update their app to the latest version immediately to ensure their security.
Apple’s Coordinated Action
Apple concurrently acknowledged the severe nature of the flaw within its own systems and subsequently issued vital security patches for iOS and iPadOS. This coordinated response from both WhatsApp and Apple underscores the gravity of the vulnerability.
Identity of Attackers Remains Unknown
As of now, the identities of the hackers or the specific spyware vendors behind these sophisticated attacks remain undisclosed. Historically, such highly targeted exploits, often leveraging ‘zero-day’ vulnerabilities – previously unknown flaws – are characteristic of state-sponsored actors or private mercenary surveillance firms seeking to surveil journalists, activists, human rights defenders, or government officials. The precise nature of the stolen information has not been detailed, but the implications for user privacy are significant.
Importance of Software Updates
This incident serves as a stark reminder of the persistent threats in the digital landscape and the critical importance of promptly installing software updates to safeguard personal data against evolving cyber threats.


