Apple Disputes Some Details of Google's Project Zero Report on iOS Security Vulnerabilities [Updated]

Google's Project Zero last week shared details about multiple serious iOS vulnerabilities that allowed malicious websites to access a victim's phone. There were a total of 14 vulnerabilities that were being exploited, and while those have now been fixed, some of the security holes were abused for several years.

Apple today responded to Google's Project Zero blog post in an effort to address customer concerns with all of the facts.

trio iphones ios
Apple says the attack was "narrowly-focused" rather than a broad-based exploit of iPhones as described. Fewer than a dozen websites targeting Uighur Muslims were affected, according to Apple. Further, Apple says that Google created a false impression of mass exploitation, causing fear among iPhone owners.

Google also got the length of the attacks wrong. Apple says the websites were operational for approximately two months rather than two years, with the vulnerabilities fixed 10 days after Apple learned about them. Fixes were already in the works when Google approached Apple.

Apple's full letter is included below:

Last week, Google published a blog about vulnerabilities that Apple fixed for iOS users in February. We've heard from customers who were concerned by some of the claims, and we want to make sure all of our customers have the facts.

First, the sophisticated attack was narrowly focused, not a broad-based exploit of iPhones "en masse" as described. The attack affected fewer than a dozen websites that focus on content related to the Uighur community. Regardless of the scale of the attack, we take the safety and security of all users extremely seriously.

Google's post, issued six months after iOS patches were released, creates the false impression of "mass exploitation" to "monitor the private activities of entire populations in real time," stoking fear among all iPhone users that their devices had been compromised. This was never the case.

Second, all evidence indicates that these website attacks were only operational for a brief period, roughly two months, not "two years" as Google implies. We fixed the vulnerabilities in question in February -- working extremely quickly to resolve the issue just 10 days after we learned about it. When Google approached us, we were already in the process of fixing the exploited bugs.

Security is a never-ending journey and our customers can be confident we are working for them. iOS security is unmatched because we take end-to-end responsibility for the security of our hardware and software. Our product security teams around the world are constantly iterating to introduce new protections and patch vulnerabilities as soon as they're found. We will never stop our tireless work to keep our users safe.

According to Google, the websites in question that targeted ‌iPhone‌ users were able to steal private data like messages, photos, and GPS location in real time with little effort after a visitor went to an infected website.

Google believes thousands of visitors accessed these websites per week over two years, with the vulnerability present in iOS 10, iOS 11, and iOS 12. Apple addressed the issues in iOS 12.1.4 back in February 2019.

In a statement to The Verge, Google said that it stands by its original report despite Apple's comments.

Project Zero posts technical research that is designed to advance the understanding of security vulnerabilities, which leads to better defensive strategies. We stand by our in-depth research which was written to focus on the technical aspects of these vulnerabilities. We will continue to work with Apple and other leading companies to help keep people safe online.

Popular Stories

airpods 4 blue

Apple Finally Explains How to Install New Firmware on Your AirPods

Monday January 27, 2025 11:17 am PST by
Apple regularly releases new firmware for the AirPods, AirPods Pro, and AirPods Max, but the company has historically provided limited information on how to initiate an update. That changed today, and Apple updated its AirPods firmware support page with more specific instructions. Prior to today, here's what Apple said on the subject: Firmware updates are delivered automatically while your...
iOS 18

iOS 18.3 Available as Soon as Today With These New Features

Monday January 27, 2025 6:35 am PST by
Update: Apple has released iOS 18.3. In its press release unveiling a new Black Unity Sport Loop for the Apple Watch today, Apple confirmed that iOS 18.3 is "upcoming." According to Bloomberg's Mark Gurman, Apple Stores are being instructed to update the software on demo devices today, so iOS 18.3 should be released either today or within the next few days. Below, we recap everything new...
tvOS 18 Thumb 3

Apple Releases tvOS 18.3

Monday January 27, 2025 10:00 am PST by
Apple today released tvOS 18.3, the newest version of the tvOS 18 operating system that came out in September. tvOS 18.3 comes more than a month after Apple released tvOS 18.2, and it is available for the Apple TV 4K and the Apple TV HD models. tvOS 18.3 can be downloaded using the Settings app on the ‌Apple TV‌. Open up Settings and go to System > Software Update to get the new software....
Generic iOS 18

iOS 18.4 Beta Coming Soon With These New Features for Your iPhone

Friday January 24, 2025 8:16 am PST by
iOS 18.3 is expected to be widely released next week, and that means the first iOS 18.4 beta for iPhones should be just around the corner. Apple has previously implied that iOS 18.4 will be released in April, as that is when it promised to make Apple Intelligence available in even more languages. Below, we outline what to expect from iOS 18.4 so far. Apple Intelligence for Siri Siri ...
iPhone 17 Pro Dual Tone Horizontal 1

iPhone 17 Pro Launching This Year With These 8 New Features

Tuesday January 28, 2025 11:48 am PST by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch until September, there are already plenty of rumors about the devices. iPhone 17 Pro concept based on rumors Below, we recap key changes rumored for the iPhone 17 Pro models as of January 2025: More aluminum: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro models ...
iOS 18

5 New Things Your iPhone Can Do in iOS 18.3

Friday January 24, 2025 1:55 am PST by
Apple is set to release iOS 18.3 next week, bringing further refinements to Apple Intelligence features, a couple of neat new capabilities to iPhone 15 Pro and iPhone 16 devices, and bug fixes. While not quite as packed with new features as Apple's preceding iOS 18 point releases, iOS 18.3 still introduces capabilities that aim to make your iPhone smarter and more intuitive. Below, we've...
iOS 18

Apple Releases iOS 18.3 With Visual Intelligence and Notification Summary Improvements

Monday January 27, 2025 10:04 am PST by
Apple today released iOS 18.3 and iPadOS 18.3, the third major updates to the iOS 18 and iPadOS 18 software that came out last year. iOS 18.3 and iPadOS 18.3 come six weeks after Apple released iOS 18.2 and iPadOS 18.2. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. Apple has also released iPadOS 17.7.4 for...

Top Rated Comments

Khedron Avatar
71 months ago
Apple is just spinning their standard "a small number of customers were affected" narrative

If they genuinely disagreed with Google's claims they'd lawyer up
Score: 32 Votes (Like | Disagree)
sulpfiction Avatar
71 months ago
Googles mission statement is to exploit it's users. Hello Kettle.
Score: 24 Votes (Like | Disagree)
AlterZgo Avatar
71 months ago
“Don’t be evil...” unless it’s an opportunity to trash your strongest competitor, then go head and lie, fabricate stuff, misstate and exaggerate.
Score: 24 Votes (Like | Disagree)
gnomeisland Avatar
71 months ago
Hope Apple does this to google. Finds vulnerabilities and work their propaganda to hurt Google
I hope they don’t. It’s very unethical. However if it was at all intentional on Google’s part I hope it gets included in their various on-going anti trust investigations.
Score: 17 Votes (Like | Disagree)
NickName99 Avatar
71 months ago
And now we know why Google didn’t release a list of the websites affected, and why they waited until right before the iPhone 11 release to talk about it.
Score: 17 Votes (Like | Disagree)
gnomeisland Avatar
71 months ago
While I generally think Apple is one of the most ethical corporations ATM, I’m not sure who to believe.

If Apple’s right, then Google’s misrepresentations are damaging, bordering on libel coming from a close competitor. Their reports did a lot of damage to the narrative that iOS is more secure than Android (not that Android hasn’t come a long way).
Score: 15 Votes (Like | Disagree)