Amnesty: HomeKit Exploit Used in Spyware Attacks on iPhones
Amnesty International has reported that a vulnerability in Apple’s HomeKit was exploited to target iPhones belonging to Serbian journalists and activists, 9to5mac.com revealed yesterday.
Following notifications from Apple about potential compromises by Pegasus spyware, the organization conducted an investigation that confirmed the attacks.
The NSO Group’s Pegasus spyware is known for its zero-click exploits, enabling hacking without user interaction, such as merely receiving a specific iMessage. Amnesty found that two victims were targeted within minutes from different iCloud accounts linked to the spyware.
Further forensic analysis revealed similar attack patterns in India, where other individuals also received alerts from Apple regarding state-sponsored attacks. While Apple has begun scanning for signs of Pegasus and notifying users, details about the HomeKit vulnerability remain undisclosed as the company works to address the issue. Android devices were also affected, and surveillance software was reportedly installed on victims’ locked phones after they sought police assistance.