Apple iPhone vulnerability ‘as bad as it gets’
By Asavin Wattanajantra in Editorial
Posted in Charlie Miller, hack, iPhone, Apple on
Charlie Miller, well known in the security world for hacking Apple’s Safari browser in seconds, has found a new vulnerability in the iPhone that security vendor F-Secure has described as “bad as it gets”.
According to the original article, the vulnerability appears to allow unsigned code to run which circumvents a core part of the iPhone’s security model. Usually it is only able to run signed code, like Apps approved by Apple.
Miller said it doesn’t even need user-interaction, and exploits a weakness in the way the iPhone’s handles SMS text messages. He wouldn’t provide more details of the problem, and it looks like Apple are trying to hurry a patch to secure the exploit.
He also claimed that the malicious code could have been used to monitor the location of the phone using GPS, turn on the phone’s microphone to listen to conversations, or even make it join a botnet or denial of service attack.
It isn’t the first time that Miller has found weaknesses in Apple products. As well as the Safari hack, in April Miller found a different weakness in the previous version iPhone.
However, he says that the iPhone OS is more secure than the full Mac OS X as it removes applications and features like support for Adobe Flash and Java, which PC users have learned is a serious weak point on Windows.
However as the Register also reports, an SMS attack is very crafty, and something very difficult for iPhone users to protect against.
Charlie Miller will reveal more at the Black Hat conference later this month.
Tag cloud
Most commented posts
- Ten reasons why people are leaving MySpace
52 comments
- My Michael Jackson blog post
- Ten reasons why World of Warcraft is better than Second Life
- Facebook user arrested for poking somebody
- What should the staff writer have as his smartphone?
- Beware of hacked Facebook applications
- Ten funny sightings on Google Street View
- Twitter didn't actually get hacked - Google did
- Microsoft sues firm for instant messaging spam
- Joining the sheep - I'm getting an iPhone
Highest Rated Blog Posts
- Ten tips to avoid your satnav driving you over a cliff (100%)
- Does unfiltered internet 'disturb children'? (100%)
- The brain-controlled laptop computer (100%)
- Why Twitter is a better news tool than Digg (100%)
- Apple and its obsession with secrecy (100%)
- Twitter isn't for teenagers? It's common sense. (100%)
- Farming and becoming a Godfather with Facebook (100%)
- Orange and the iPhone - competition is a good thing (100%)
- Bendy phones straight out of the future (93.4%)
- How Pirate Bay sticks two fingers up at the industry (80%)

