Spyware poses a serious threat

ADEO Cyber Security expert Ersin Çahmutoğlu has issued a warning regarding security vulnerabilities in Apple products.

AA

Following the detection of security vulnerabilities in iPhones by Kaspersky last June, discussions regarding security flaws in Apple products have returned to the agenda due to breaches in the brand's messaging application, iMessage.

Speaking to an AA reporter, ADEO Cyber Security expert Ersin Çahmutoğlu stated that four different security vulnerabilities were identified in iPhones and other Apple products last June.

Noting that the Russian intelligence service FSB and Kaspersky made this discovery and that the vulnerabilities are highly critical, Çahmutoğlu said, “One of the vulnerabilities makes it possible to send malicious software via an attachment in the iMessage application. The other vulnerabilities are located at the core operating level of iPhones, known as the kernel. These flaws were detected in the unit that acts as a bridge between hardware and software and contains security layers. Because it is at the kernel level, these vulnerabilities are much more critical. Spyware that infects devices through these vulnerabilities operates without showing any signs on the device. The infection process is also interesting. It does not require interaction from the target. In other words, there is no need to click or open anything. All of this makes these vulnerabilities dangerous because those who exploit them can both take control of the phone and exfiltrate the data within it.”

“They can access devices whenever they want”

Stating that according to Kaspersky, there was no intent in this incident but that the flaw was not a simple one, Çahmutoğlu said, “The Russian intelligence service FSB, however, explicitly states that this is a backdoor requested from Apple directly by the US intelligence agency, the NSA. The reason for these two different approaches lies in political and commercial interests. There are deeper issues underlying this matter. When we look at the technical data, we can say that this is a backdoor. Because there is a cyber espionage operation that has been going on for years, and let alone the most powerful hackers, even states with mid-level cyber power cannot do this. All arrows point to the US.”

Pointing out that thanks to this vulnerability, US intelligence services could access devices whenever they want, Çahmutoğlu assessed, “Technical examinations conducted through these critical vulnerabilities show this. We are seeing a very complex and sophisticated operation. This is also mentioned in the findings.”

Çahmutoğlu stated that there is an investigation launched by the BTK (Information and Communication Technologies Authority) regarding the issue and that information has been requested from Apple. Çahmutoğlu added the following:

“I would like to specifically state this; Turkey's findings may not be the same as Kaspersky's. Even though we see what is in the Kaspersky report when we look at the command and control servers used in the cyber espionage operation in question, which are located at the National Cyber Incident Response Center (USOM), there may be additional situations here. In other words, USOM may have things in addition to the findings of Kaspersky and the Russian intelligence service FSB. We might even be facing a completely different incident. We have not yet seen the details. We may learn them in the coming period.”