China uses the iOS vulnerability to monitor Uighur Muslims
China uses the iOS vulnerability to monitor Uighur Muslims

Volexity Cybersecurity has discovered a new iOS vulnerability that has been used to monitor Uighur Muslims in China. Vulnerability Volexity is described as (insomnia). Versions are 12.3, 12.3.1, and 12.3. 2 from the operating system (iOS).

In July 2019, Apple fixed several vulnerabilities in its mobile operating system with the iOS 12.4 update, including several vulnerabilities in the open source WebKit engine. However, Volexity researchers said that at least one of these vulnerabilities was released in January 2020. It was actively used in March 2020.

This vulnerability allowed the attacker to access the root user on the device and used it after the user visited a website with Chinese Uyghurs and various text messages from email programs, emails, photos, contact lists and geolocation data.

According to Volexity, the attacks were funded by the Chinese government and carried out by hacked organizations to spy on Uighur Muslim minorities. The organization is called Evil Eye. The company also believes that the piracy organization itself has carried out a number of attacks against Uyghurs by exploiting vulnerabilities in iOS. ) Was discovered by Google in August 2019.

Since 2016, the organization has used up to 14 security gaps to monitor Uighur Muslims in China. Compared to previous security vulnerabilities, Insomnia has been expanded to include encrypted applications such as ProtonMail and Application (Signal) messages.

Researchers believe this indicates that a small number of Uyghur Muslims in the Xinjiang Autonomous Region were aware of the vision and were trying to use coded applications to avoid this, and that insomnia is a security vulnerability, based on WebKit that can be done on anyone who can use the device. Launch the browser (iOS) such as (Safari) and (Chrome).



Previous Post Next Post