Researcher sends malicious app into Apple App Store

Sneaking past Apple's App Store proves successful, but the researcher who discovers the flaw is thrown off the iOS developer programme.

iPhone 4S

A software hole in Apple's iPhone and iPad devices may permit developers to break through the App Store gates and control the device.

Security researcher Charlie Miller discovered the flaw, allowing developers to bypass the code signing restrictions and secretly install malware onto Apple devices.

"The flaw I found allows apps in the App Store to download new code and run it even if it's not signed or even if it hasn't been checked by Apple," Miller said in his YouTube clip below.

"Until now you could just download everything from the App Store and not worry about it being malicious. Now you have no idea what an app might do," said Miller.

Miller demonstrated the flaw by using a stock price checking application he created, InstaStock, which was approved even though it contained features to download unapproved code.

The app's code could let a hacker download an address book, view pictures, access other data and even make the phone vibrate.

Despite attempting to highlight security flaws in Apple's systems, because he had broken Apple's App Store rules, Miller was thrown off the iOS developer programme.

"Apple just kicked me out of the iOS Developer program. That's so rude," Miller tweeted on Monday. "First they give researcher's access to developer programs, (although I paid for mine) then they kick them out for doing research. Me angry."

"Just found out not only am I kicked out, I can't come back for a year. 1 year suspension," Miller tweeted today.

Apple has now removed the app from its App Store.

Featured Resources

BCDR buyer's guide for MSPs

How to choose a business continuity and disaster recovery solution

Download now

The definitive guide to IT security

Protecting your MSP and your customers

Download now

Cost of a data breach report 2020

Find out what factors help mitigate breach costs

Download now

The complete guide to changing your phone system provider

Optimise your phone system for better business results

Download now

Recommended

Apple doubles down in the US with $430 billion investment
business intelligence (BI)

Apple doubles down in the US with $430 billion investment

27 Apr 2021
App makers take shots at Apple in Senate hearing
Development

App makers take shots at Apple in Senate hearing

22 Apr 2021
HackBoss malware is using Telegram to steal cryptocurrency from other hackers
cryptocurrencies

HackBoss malware is using Telegram to steal cryptocurrency from other hackers

16 Apr 2021
Data breach exposes widespread fake reviews on Amazon
data breaches

Data breach exposes widespread fake reviews on Amazon

7 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

29 Apr 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021