Apple Patched An iPhone Vulnerability, Months After China Exploited It, Reports Said

As one of the most popular smartphone maker, Apple is making sure that it patches every single bug and vulnerability it finds, and whatever that has been reported to it.

But what happens when a vulnerability is not informed to Apple, and instead being used by government-backed hackers?

Back in 2019, Apple wrote in a Newsroom post, saying that it had patched a security vulnerability in its iOS operating system. The attack that had exploited the vulnerability, Apple said, was “narrowly focused” on websites featuring content related to the Uighur community.

However, it has emerged that the vulnerability in question was first discovered at China’s hacking competition, the Tianfu Cup, where a professional hacker won a prize for his work in uncovering it.

And here, it's alleged that Apple was not the first to be informed by this.

The breach was left unknown to Apple for a duration of time, with the Chinese government acquiring it to spy on the country’s Muslim minority.

iPhone hack
Credit: Vice.com

It began in March 2017, when a group of Chinese hackers went to Vancouver in Canada, with a goal to find bugs and vulnerabilities inside some of the most popular platforms and technologies.

As usual, products from Apple, Google, Microsoft and some others are the priorities, knowing that they have the most amount of users.

At that time, it was Pwn2Own's 10th anniversary. At the event where elite hackers from around the globe can earn big cash prizes if they can find and create exploits, it's required that every flaw that is found should be handed over to the companies involved, giving the developers the time to fix the issue.

Chinese hackers were among the most dominant in hacking events like Pwn2Own, with many of them walking away with financial rewards accounting to millions of dollars in prizes, as well as eternal bragging rights among the elites.

But in 2017, that all stopped.

This was emphasized by a statement by the billionaire founder and CEO of the Chinese cybersecurity giant Qihoo 360.

The leader of the one of the most important technology companies in China publicly criticized Chinese citizens who went abroad to take part in hacking competitions. In a post following his interview with the Chinese news site Sina, he said that hackers who performed well in such events will only see “imaginary” success.

Zhou warned that once Chinese hackers show off vulnerabilities at overseas competitions, they can “no longer be used.”

Instead, the hackers and their knowledge should “stay in China” so that they could recognize the true importance and “strategic value” of the software vulnerabilities.

Read: China Is Installing Spyware App For People Entering The Xinjiang Region

[block:block=87]

This was to some extent, a true statement, since months later, the Chinese government banned cybersecurity researchers from attending hacking competitions outside of China, and instead created local competitions to replace the international contests.

And its name is the 'Tianfu Cup'.

Through the event, it's reported that it's one of the ways China can ensure that hackers have a place to show their knowledge and skills, and prevent them from going abroad to share their findings. The event is like China's desire to keep discovered vulnerabilities inside of China.

And it was in 2018, that Qihoo 360 researcher Qixun Zhao managed to hack and take control of even the newest and most up-to-date iPhones.

Qixun named it the “Chaos.”

That bug was not quickly reported.

And it was only later revealed that the Chinese intelligence used it as a weapon to track minority ethnic group Uighur.

In other words, China and its hackers have turned down a prize-winning iPhone, to have that exploit to remain.

This kind of hack can cost millions in the market, and Apple is even willing to pay millions of dollars to cybersecurity researchers to they don't blurt it out to the public before it is fixed.

Through Tianfu Cup, China is attempting to ensure that it can prevent top Chinese hackers from earning money from other sources outside China, and come in contact with foreign state or foreign companies.

Qihoo 360 and Tianfu Cup did not respond to multiple requests for comment. Qixun Zhao however, denied any involvement.

He only said that he couldn’t remember who came into possession of the exploit code, and suggested that the exploit was probably used “after the patch release.” This is a contrast to what both Apple and Google have said, in which the two documented how this exploit was used before January 2019.

Qixun Zhao
Qixun Zhao explaining vulnerabilities he and his team found on iOS and Safari at MOSEC 2018.

It has been for years, that the Chinese government is accused for abusing the Uighur people and other minority groups in the Western province of Xinjiang.

Xinjiang, the provincial-level Chinese autonomous region in the northwest, is regarded as the largest Chinese administrative division and the 8th largest country subdivision in the world, that spans over 1.6 million square-kilometers.

The region is the home for a number of minority ethnic groups, which include Uyghur which are mostly muslims, Han, Kazakhs, Tibetans, Hui, Tajiks, Kyrgyz, Mongols, Russians and Xibe.

These minorities are subjected to Chinese surveillance.

Xinjiang also has facilities where China experiments in new technology and surveillance systems. Some of the technology that came out of these laboratories are used on the Uyghurs, before being implemented elsewhere in China, or sold abroad.

China denied the existence of such activities and detention centers for Uyghurs, by referring those places as "vocational education centers."

Surveillance is nothing new in China, as cameras equipped with AI and facial recognition can be found in many places throughout its cities.

Further reading: More Chinese Companies Have Patents For AI-Powered Uighur Detection, Research Found