Google Discovered a New Attack on Older iPhones

Google знайшла нову атаку на старі iPhone
Google знайшла нову атаку на старі iPhone

Google reported a new chain of attacks that was used against outdated iPhones. This is not about a single vulnerability, but a combination of multiple flaws that allowed attackers to bypass iOS protections. This means the issue is deeper than it may seem at first glance.

The attack is based on a so-called exploit chain — when several vulnerabilities are combined into a single attack scenario. These types of attacks are the most dangerous because they allow attackers to gain near full control over a device. In this case, the targets were specifically older iPhone models.

What Google discovered and why it matters

The Google Threat Analysis Group reported a new attack that used multiple iOS vulnerabilities at once. Importantly, these vulnerabilities were already known and had been fixed in newer versions of the system. However, the problem is that not all users update their devices.

That is why the attack specifically targeted outdated iPhones that no longer had the latest security updates. This is not random, but a deliberate strategy. Older devices always become the weakest link.

In such scenarios, attackers can use a browser or other services as an entry point. Then an exploit chain is triggered, allowing access to the system. The user may not even notice that anything has happened.

How the exploit chain works in practice

A single vulnerability rarely provides full access to a device. But when several are combined, the situation changes. This is exactly what happened in the case of iPhone.

The attack typically begins with initial access — for example, through web content. Then another vulnerability is used to escalate privileges. As a result, the system can be fully compromised.

This approach is harder to detect and stop. It requires more resources but delivers much better results for attackers. That is why such attacks are used in targeted campaigns.

Why older iPhones are the target

Apple regularly releases security updates. But not all devices receive them indefinitely. At some point, support ends.

This means new vulnerabilities are no longer patched. Over time, the device becomes more vulnerable. Especially if it is actively used online.

That is why older iPhones become ideal targets. They still work, but are no longer protected like newer models. This creates a risk that many users underestimate.

What this means for users

At first glance, this may seem like a technical story. But in reality, it is about everyday smartphone use. And about how secure your device actually is.

If an iPhone no longer receives updates, it gradually moves into a risk zone. This does not happen instantly, but the process is irreversible. Each new vulnerability makes the situation worse.

With exploit chains, the risk increases even further. The attack is not limited to a single flaw. It becomes a complex scenario that is difficult to stop without system updates.

What you should do right now

The first and most important step is to check whether your iPhone is receiving updates. If updates are available, they should be installed immediately. This is the basic level of protection.

If your device is no longer supported, you should consider upgrading. This is not about performance or camera quality. It is about security.

It is also important to be cautious with websites and content. Most attacks begin there. Even basic awareness can reduce risks.

Why this matters for the market

This is not the first time Google has uncovered complex attacks targeting iOS. But each such report highlights one key point. Security is a process, not a state.

Even closed ecosystems are not completely secure. The difference between a safe and a vulnerable device often comes down to updates. This is changing how people choose smartphones.

As a result, users are paying attention not only to specifications. They are also looking at support lifecycles. This is already influencing the market as a whole.

Is an old iPhone already a risk

An old iPhone does not become dangerous instantly. But risks increase over time. This needs to be taken into account.

This is especially important if the device is used for banking, email, or work. In such cases, security is critical. Compromises can be costly.

That is why reports like this matter. They reflect the real state of things. And help users make more informed decisions.

Which iPhones are protected and which are at risk

In this case, the key factor is not the iPhone model but the iOS version. If a device receives the latest security updates from Apple, it is protected against known exploit chains. This means the attack reported by Google does not work on up-to-date systems.

Apple випустила iOS 26.4 RC (23E244) та оновлення для всіх платформ

20.03.2026

Apple випустила iOS 26.4 RC — фінальну версію перед релізом, і цього разу оновлення не обмежилось виправленнями. Компанія виправила баг клавіатури, додала нові функції в Apple Music і оновила систему. Публічний запуск очікується вже найближчими днями.

At risk are iPhones running older versions of iOS. These include devices that are no longer supported as well as those that simply have not been updated. In this state, they remain exposed to known vulnerabilities.

It is important to understand that even a relatively new iPhone can be vulnerable without updates. Security depends not on the release year but on the system version. That is why Apple constantly encourages users to install new iOS versions.

If a device no longer receives updates at all, the situation changes significantly. Every newly discovered vulnerability remains unpatched. Over time, these weaknesses accumulate.

That is why unsupported iPhones are the highest-risk group. They may still perform well, but they no longer receive protection. This is something many users underestimate.

Which iOS versions fix the vulnerabilities and what to install

After the reports were published, Apple released iOS 16.7.15 and iOS 15.8.7, as well as iPadOS 16.7.15 and iPadOS 15.8.7. These updates fixed kernel and WebKit vulnerabilities that were used in the attacks. This means even older devices received a baseline level of protection.

Separately, the Google Threat Intelligence Group listed a number of vulnerabilities used in the exploit chain. These issues were assigned CVE identifiers and were patched across different iOS versions. They formed the foundation of the more advanced attack.

  1. CVE-2025-31277 — fixed in iOS 18.6.
  2. CVE-2026-20700 — fixed in iOS 26.3.
  3. CVE-2025-43529 — fixed in iOS 18.7.3 and iOS 26.2.
  4. CVE-2025-14174 — fixed in iOS 18.7.3 and iOS 26.2.
  5. CVE-2025-43510 — fixed in iOS 18.7.2 and iOS 26.1.
  6. CVE-2025-43520 — fixed in iOS 18.7.2 and iOS 26.1.

This means devices running iOS 18.7.3, iOS 18.7.2, iOS 18.6 or newer already address part of these vulnerabilities. Full protection is provided by newer system branches, including iOS 26.3 and iOS 26.2. All earlier versions remain potentially vulnerable.

It is important to understand that this is not about a single version, but a group of updates. Each new iOS release patches parts of the exploit chain. That is why updates should be installed as soon as they become available.

If an iPhone is running iOS 15.8.7 or iOS 16.7.15, it receives basic fixes for older models. However, full protection is only available on newer versions of the system. This is the key difference between “still working” and “secure.”

More news on Telegram
telegram button

More interesting articles
More interesting articles


Більше новин в телеграмі telegram button


Адмін Гік
Адмін Гік
Copywriter, SEO specialist and web developer at UITech

I am a copywriter, SEO specialist, and web developer with professional experience since 2009. I build fast, user-friendly websites and focus on long-term search visibility, technical optimization, and clean structure. I work across multiple operating systems and tools, combining content creation, usability, and technical expertise.

I’m passionate about gadgets and closely follow technology trends. I write in-depth device reviews, industry news, and analytical articles. I test products in real-life scenarios, photograph them, and turn hands-on experience into practical, reliable content.
At UITech.com.ua, I create technology-focused materials that help readers choose the right devices — from smartphones and laptops to software and creative tools.

Leave a Reply

Your email address will not be published. Required fields are marked *