So this week I actually installed a security update the same day it came out, which if you know me is basically a personality transplant. Normally those "Update Now" badges sit on my phone for like three weeks while I tell myself I'll get to it. Not this time.
Apple pushed out iOS 16.6.1 on Thursday (Sept 7) to patch two zero-day vulnerabilities that were being actively used in the wild, not theoretical, not "a researcher found this in a lab," actually deployed against actual humans. Citizen Lab, the research group out of University of Toronto that's been tracking spyware for years, found the exploit chain on the phone of someone working at a DC-based civil society org and traced it to NSO Group's Pegasus spyware. They're calling the chain BLASTPASS, and the two CVEs are 41064 and 41061 if you want to look them up.
The part that gets me every time is "zero-click." You don't tap a bad link. You don't open a sketchy attachment thinking it's a boarding pass. The exploit came through a malicious attachment sent via iMessage, PassKit specifically, so like a wallet pass, and it just works on your phone without you doing anything at all. No dumb decision required on your part. That's the thing that always breaks my brain a little, because most of the security advice I grew up giving people (don't click that, don't open that email) assumes the victim has to participate somehow. This one doesn't need you to participate. It just needs your phone to receive a message.
Apple's patch note is doing that thing they always do where it's incredibly clinical: "Processing a maliciously crafted attachment may lead to arbitrary code execution." Sure. Fine. What that sentence actually means is someone could end up with a fully compromised phone, mic, camera, messages, location, all of it, without a single suspicious click to warn them. The fix rolled out for iPhones, iPads, and I believe watchOS and macOS Ventura got matching patches too since a lot of these components are shared across the OS family now.
I want to be clear this isn't really an "everyone panic" post. Pegasus-style spyware is expensive, it's targeted, and the people getting hit with it are journalists, activists, dissidents, folks who are specifically interesting to a government or someone with government-level money. It is almost certainly not aimed at me writing a blog about USB cables and RSS feeds. But that's kind of exactly why I updated immediately instead of my usual three-week procrastination window, once a chain like this becomes public knowledge, the exploit itself doesn't stay a secret weapon for long. The techniques get studied, sometimes reverse engineered, and lower-effort copycats start showing up. The window between "elite targeted attack" and "random garbage floating around" tends to close faster than people expect.
Also, small aside because I can't help myself: this is what, the fourth or fifth actively-exploited zero-day Apple's patched just this year? I stopped counting exactly, but it's been a lot for a company whose whole marketing pitch for over a decade has been "it just works, safely, don't worry about it." I still think iOS security is genuinely better than the alternative for most regular people. I just don't buy the mystique anymore that Apple devices are some unbreachable fortress. Nothing connected to the internet is, and pretending otherwise is how people end up not updating for a month.
Anyway. If you've got an iPhone and you're one of the "I'll do it later" people (no judgment, I am also that person 90% of the time), go check Settings > General > Software Update right now. Takes five minutes. And yes, I know Apple's big iPhone 15 event is Tuesday and everyone's about to be buried in USB-C takes and titanium chassis talk, this felt like the more useful thing to actually write about before that circus starts, since half the internet is going to be covering the new phones and approximately nobody is going to mention that you should probably patch the one you already have first.
Go update your phone. That's really the whole post.