Photo by Creative Commons

iOS 14.8: Not your average Apple update

Did you get an alert three weeks ago saying you needed to update your iPhone? Well then stop what you’re doing, check your settings, and update your phone right now. This update may be the most important one to date; the iOS 14.8 update is designed to protect your Apple devices from being hacked without even needing to enter a link.

The iOS 14.8 update is designed to protect your Apple devices from being hacked without even needing to enter a link.

This vulnerability was discovered by the University of Toronto’s Citizen Lab in March 2021, according to the lab’s website, when the lab examined a Saudi activist’s phone infected with Pegasus spyware. Pegasus spyware is software that can be used to hack into a person’s device and was developed by an Israeli company NSO. NSO has licensed this software to many international governments. When examining the phone, researchers discovered an exploit nicknamed FORCEDENTRY that attacks Apple’s ability to produce PDFs. What makes this exploit unique is that it can be installed on your Apple product in mere seconds without using a link — hence the name “zero-click.”

Once FORCEDENTRY enters your device, it can perform a wide range of actions — from using your camera to sending your messages to foreign parties. “This spyware can do everything an iPhone user can do on their device and more,” John Scott-Railton, a senior researcher at Citizen Lab, said to The New York Times.

Apple has fought back by releasing iOS 14.8. This update fixes a variety of bugs in Apple’s software, such as how Apple handles its memory or how Apple properly checks any variables that are input into its system to avoid an overflow of information. Without the update, if your device processes an “infected” pdf, it executes code that allows the hacker into your device. Another way a hacker could enter your phone is if the user clicks on a bugged website.

Although Ivan Krstić, Head of Security Engineering and Architecture for Apple, said the attack won’t affect the majority of its users, this update is highly recommended as a safety precaution.