Apps & Consumer
Apple says Lockdown Mode has resisted all spyware attacks
Apple reports that no devices with Lockdown Mode enabled have been successfully hacked by mercenary spyware, though the company notes it is possible attacks have gone undetected.
Almost four years after launching its Lockdown Mode security feature, Apple has stated it has not seen a case where a user’s device was hacked with the protections enabled. On Friday, Apple spokesperson Sarah O’Rourke told TechCrunch, “We are not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device,” referring to mercenary spyware, which is spyware sold to governments to target individuals. Since introducing the opt-in feature in 2022 to help customers defend against threats from spyware makers like Intellexa, NSO Group, and Paragon Solutions, the company has sent notifications to users in over 150 countries warning them that they may have been hacked with spyware. While Apple has not disclosed the exact number of affected users, it is likely that dozens, if not more, have received these alerts, demonstrating the scale of the company’s visibility into these spyware attacks.
Digital rights and research organizations have backed Apple’s assessment. Donncha Ó Cearbhaill, the head of the security lab at Amnesty International, stated that his team has not seen any evidence of an iPhone being successfully compromised by mercenary spyware where Lockdown Mode was enabled at the time of the attack. Similarly, researchers at Citizen Lab, a university research organization documenting spyware attacks, have documented at least two cases where Lockdown Mode actively blocked spyware attacks—one involving Pegasus spyware from NSO Group, and another involving Predator spyware from Intellexa. Additionally, security researchers at Google observed that some spyware would likely bail out of infection attempts if it detected Lockdown Mode, a tactic likely used to evade detection.
Patrick Wardle, an Apple cybersecurity expert and critic, described the tool as a defense, calling it one of the most aggressive consumer-facing hardening features ever shipped. Wardle explained that the feature kills entire delivery mechanisms and exploit classes by blocking most message attachment types and restricting WebKit features. This significantly reduces the attack surface, particularly against zero-click exploit chains, which are hacks that target people over the internet without any interaction from the victim. However, it remains possible that Lockdown Mode has been bypassed without detection by Apple or researchers.
Why it matters
Apple’s statement marks a significant milestone for the effectiveness of its Lockdown Mode security feature, which the company claims has successfully withstood government spyware attacks since its 2022 launch.