Global security desk · updated coverage of threats, exploits & breaches

Silent iMessage: zero-click exploit reaches Australian iPhones

A newly disclosed zero-click attack chain targeting iOS devices through iMessage has put Australian iPhone users and the businesses that rely on them on high alert. Researchers at a European security firm identified the campaign after a suspicious message reached an executive's handset in late August, and the findings have since circulated through industry channels, including SecNews24 coverage. The exploit requires no taps, no links and no user interaction, which makes it especially dangerous for journalists, lawyers, finance teams and senior public servants in Sydney, Melbourne and Canberra who routinely discuss sensitive matters through chat.

Australia remains one of the most iPhone-dense markets in the Asia-Pacific region, with the device claiming a clear majority of the smartphone share across major operators and a particularly strong presence among executives at ASX-listed companies. That concentration means a single iMessage vulnerability can reach an outsized slice of the local workforce in a single morning. Security teams at banks in Sydney's Macquarie Park, mining houses in Perth and federal departments in Canberra are already fielding questions from boards about whether their managed handsets are exposed.

The threat arrives against a backdrop of tightening Australian regulation. The Privacy Act and the Notifiable Data Breaches scheme mean that any compromise of customer or employee data on a corporate device can trigger obligations to the Office of the Australian Information Commissioner. APRA's CPS 234 standard adds another layer for banks, requiring them to demonstrate that information assets remain resilient. Zero-click surveillance chains that quietly siphon contacts, messages and location data are exactly the kind of incident that can land a regulated entity in breach of those rules.

What marks this campaign apart from ordinary phishing is its delivery mechanism. The malicious payload is hidden inside an iMessage attachment that the operating system processes automatically, before the recipient even sees a notification. Once parsed, the attachment triggers a chain that researchers compare to the notorious Pegasus and BLASTPASS incidents, ultimately giving the operator remote access to the device without ever alerting the user.

Anatomy of the exploit chain

The intrusion begins with a specially crafted iMessage that contains a malformed image or PDF inside an otherwise invisible attachment. Apple's iOS automatically renders the preview in the background to decide whether to show the user a thumbnail, and that rendering step is where the first vulnerability lives. By exploiting a flaw in the image parsing library, the attackers gain an initial foothold in the iMessage sandbox before the message is ever marked as read.

From that first foothold, the chain escalates in stages. The attackers use a memory corruption bug to break out of the rendering sandbox and reach a process with broader system privileges. A second-stage payload then leverages an entitlement confusion flaw to read files that should be off-limits, including the Keychain entries that store credentials for email, banking apps and corporate single sign-on portals common across Australian enterprises.

Once the attackers have Keychain access, they establish persistence by registering a malicious LaunchDaemon and abusing Apple's push notification service to stay in contact with the handset even after a reboot. From there the operators can pivot into microphone and camera streams, pull recent messages from WhatsApp, Signal and the local Mail app, and silently transmit everything through an encrypted tunnel to attacker-controlled infrastructure.

Cloud infrastructure abused for delivery and command

One of the more interesting findings in the post-mortem is how the operators leaned on mainstream cloud platforms to hide their traffic. The malicious attachments were stored on a public content delivery network, and the follow-up payloads were retrieved from what looked like a routine cloud function. By piggybacking on legitimate services, the attackers avoided many of the IP-based blocklists that Australian SOC teams typically rely on.

Researchers mapped the traffic patterns in detail and concluded that the operators were using cloud-based relays in a way that is becoming common in mobile surveillance kits. Coverage of similar tradecraft, including reporting on legitimate cloud abuse, shows that iOS campaigns are no longer the only ones weaponising these platforms. Android and macOS operators are doing the same, which is forcing defenders to rethink what counts as a trusted domain.

For Australian responders, the operational consequence is that traditional firewall rules and DNS blocklists are largely blind to this traffic. The malicious requests blend in with regular Apple push traffic and routine cloud synchronisation, so only behavioural analytics on the device itself can spot the anomaly. Telstra, Optus and the major banks already run mobile threat defence platforms on parts of their managed fleets, but coverage of executive and contractor devices remains uneven.

How the iOS sandbox was broken

The iOS sandbox is designed to confine even a compromised process like the iMessage renderer to a narrow set of capabilities. Breaking out typically requires chaining together several vulnerabilities, and the operators behind this campaign appear to have assembled a four-stage chain that defeats multiple layers of Apple's mitigation. The first stage defeats pointer authentication codes, the second defeats memory tagging, the third defeats sandbox profiles, and the fourth achieves kernel-level execution.

Apple's BlastDoor service, introduced after the FORCEDENTRY exploit of 2021, normally inspects incoming iMessage attachments for malicious patterns. The new chain appears to evade BlastDoor by using a file format that is rarely seen in mainstream messaging, exploiting a parser that is processed before BlastDoor's filters engage. The result is that the attachment reaches the vulnerable library untouched, slipping past a control that was specifically designed to stop this class of attack.

The kernel-level exploit itself draws on techniques borrowed from public offensive research, but combines them in a way that appears novel. Australian security researchers at CSIRO's Data61 and several university groups have noted that the chain uses a race condition that only succeeds under specific timing constraints, making it harder to reproduce in a lab. That reproducibility problem delays patching and complicates Apple's own forensic analysis, which means organisations cannot simply wait for an official advisory to act.

Forensic traces and detection signals

When a zero-click exploit lands successfully, the device itself shows very little. There is no notification, no SMS and no visible app residue. The forensic artefacts left behind are subtle: a brief spike in CPU usage while the attachment renders, a single outbound connection to an unfamiliar cloud endpoint, and a small write to the Keychain access log that most endpoint agents do not monitor.

Australian incident responders have a few tools that can help. Mobile threat defence products from vendors including Lookout, Jamf and Sophos can flag unusual iMessage processes and alert on LaunchDaemon changes. Network detection platforms can correlate the short-lived outbound connection with other telemetry from the same handset, even when the destination looks like a routine cloud service. Apple's own logs, when extracted through a forensic image, show the tell-tale signature of the LaunchDaemon write.

Campaign Year Delivery vector Sandbox bypass stages Persistence mechanism Patch timeline
Pegasus (Trident) 2016 Safari webkit redirect 3 Kernel implant with jailbreak ~10 days after sample
FORCEDENTRY 2021 iMessage GIF 2 BlastDoor evasion, kernel RCE Issued same day as disclosure
BLASTPASS 2023 iMessage image 2 PassKit attachment, kernel exploit Issued same day as disclosure
Current campaign 2025 iMessage hidden attachment 4 Push notification persistence, Keychain abuse Patch pending analysis

The current campaign stands out for the length of its chain and the deliberate use of cloud-based relays rather than dedicated attacker infrastructure. That combination is likely to set the template for mobile surveillance kits for the remainder of the year and is the reason ASIO and the Australian Cyber Security Centre have been quick to brief critical infrastructure providers about the techniques involved.

Defensive playbook for Australian iPhone users

Australian organisations that issue iPhones to staff, or that allow staff to bring their own devices under a BYOD model, should treat this campaign as an active threat and adjust their posture now rather than after a patch lands. The window between public disclosure and widespread exploitation has shrunk dramatically in recent years, and zero-click chains are particularly prized by state-aligned groups targeting critical infrastructure, which Australia has identified as a priority concern under the Security of Critical Infrastructure (SOCI) Act.

For an executive at a Sydney-based bank or a Perth mining house, the practical steps are concrete. Lock down which applications can render iMessage previews through mobile device management, force a reboot of managed devices at the end of each working day so that any LaunchDaemon persistence is disrupted, and review Keychain access logs for unusual reads. Australian Cyber Security Centre guidance on the Essential Eight already calls for application control and patching cadence that, if applied to mobile fleets, blunt a wide range of similar attacks.

The following checklist summarises the priority actions for security teams who manage or advise on Australian iPhone deployments:

For individuals in Adelaide, Brisbane or regional centres who rely on iPhones for their livelihood, the message is simpler: keep the device updated, switch on Lockdown Mode if the threat model warrants it, and treat any unexpected battery drain or data usage spike around iMessage as a reason to seek a forensic review. Australia's relatively compact mobile market and its strong regulatory framework make it possible for defenders to coordinate a response more quickly than in larger jurisdictions, but only if users and organisations act before the next campaign arrives.