A team of Google bug researchers say they discovered six flaws in Apple’s iMessage app, one of which is yet to be fixed.
The firm’s Project Zero is made up of security analysts who hunt for serious vulnerabilities in various software before hackers find them, providing manufacturers with a 90-day deadline before they make the issue public.
The issues could have been exploited in a number of ways, such as remotely accessing files or crashing devices.
Five of the flaws were patched in the iOS 12.4 update rolled out last week, but the sixth alleged bug remains open, which Google is not disclosing until the deadline is reached.
Natalie Silvanovich, one of the researchers who uncovered the flaws, described them as “interactionless”, meaning they can run without the user having to do anything.
The only way one issue could be fixed on an iPhone was by carrying out a complete reboot and recovery leading to data loss, Ms Silvanovich said in her original report in April.
“For the protection of our customers, Apple doesn’t disclose, discuss, or confirm security issues until an investigation has occurred and patches or releases are generally available,” an Apple spokesman said.
“Keeping your software up to date is one of the most important things you can do to maintain your Apple product’s security.”
Project Zero was formed in 2014 with the aim of reducing the number of people harmed by targeted attacks.
It has previously notified the likes of Microsoft and Facebook about vulnerabilities on their services and platforms.