$bbtitle
Apple Stock: 258.77 ( +6.60 )
RSS RSS Twitter Twitter
Search:
AppleInsider.com Archives News Bytes Reviews Anonymous Mailer Submit Story AppleInsider Forums Mac Prices Polls Advertise on AppleInsider Contact AppleInsider
Hot Topics: Apple TV, iPod nano, iPod touch, iPod shuffle, iTunes 10, iOS 4.1, iOS 4.2
Save up to $300 on MacBook Pros, $180 on iMacs, and $150 on MacBooks: Mac Pricing Guide updated September 4th (Find the best prices on Macs).
Share
Thursday, July 2, 2009

Apple working to fix unreleased iPhone SMS exploit

By Neil Hughes

Published: 03:00 PM EST

Tipped off by a Mac OS X security expert, Apple is working to repair a serious security flaw in the iPhone’s operating system – one that could allow an attacker to track the phone’s location via GPS, eavesdrop on conversations via the microphone, or create a mobile bot net capable of unleashing denial of service attacks.

The attack takes advantage of a vulnerability in the phone’s short messaging service, or SMS, feature, allowing an outside party into the phone’s root access without the owner’s knowledge. Security researcher Charles Miller, co-author of The Mac Hacker’s Handbook, announced his discovery Thursday at the SyScan Conference in Singapore, according to Computerworld.

Apple plans to have the fix released later this month, before Miller gives his scheduled speech at the Black Hat Technical Security Conference in Los Angeles. At the July 25-30 conference, Miller will be joined by Colin Mulliner for a talk entitled “Fuzzing the Phone in Your Phone,” which will show attendees how to discover vulnerabilities in a variety of smartphones.

Miller has not specifically detailed how the SMS exploit is done, citing an agreement with Apple. But he will discuss the attack in length at the Black Hat conference.

The exploit takes advantage of the fact that SMS can send binary code to an iPhone. That code is automatically processed without user interaction, and can be compiled from multiple messages, allowing larger programs to be sent to a phone.

For a widely-adopted platform, Apple’s iPhone has had remarkably little in the way of discovered vulnerabilities in its short history. In 2007, a security firm – including Miller – notified Apple of the phone’s first security flaw, soon after the hardware had been released. It was subsequently fixed by Apple.

Miller said that the iPhone’s stripped-down version of OS X makes it more secure than the full-fledged operating system. And because it lacks support for Adobe Flash and Java, isolates individual applications from one another, and only allows software that has been digitally signed by Apple, it is less likely to have security flaws than a full-form computer.

Filed under : iPhone 23 Comments ] 
Story topics: Security   Print ] [ Story Link ] 

Mac Connection End of Summer Sale
MBP Model
Price
Discount
MacBook Model
Price
Discount
2.40GHz 13" MBP $1,049.00 $150.00 2.4GHz 13" MacBook $849.00 $150.00
2.66GHz 13" MBP $1,299.00 $200.00
iMac Model
Price
Discount
2.40GHz 15" MBP $1,599.00 $200.00 3.06GHz 21.5" iMac $1,049.00 $150.00
2.53GHz 15" MBP $1,729.00 $270.00 3.20GHz 21.5" iMac $1,349.00 $150.00
2.66GHz 15" MBP $1,899.00 $300.00 3.20GHz 27.0" iMac $1,529.00 $170.00
2.53GHz 17" MBP $1,999.00 $300.00 2.80GHz 27.0" iMac $1,819.99 $180.00
RSS


AppleInsider Features
Hot Forum Topics

Recent Articles
Android gaining on Apple iOS in mobile web market share
Ping draws over 1 million users in first 48 hours
iOS 4.1 on iPhone 3G shows marked improvement in speed test
iPhone expected to become multi-carrier in Germany by October
Apple now offers HTML5-based movie showtimes, locations
Apple's iOS tops Linux to become third largest browsing platform
Ping, Apple's music social network, already plagued with spammers
Apple now building 2M iPads per month to meet demand
Apple posts iPad iOS 4.2 "Coming Soon" page
Google planning music store to take on Apple
First look: Taking HDR photos with Apple's iOS 4.1
Apple issues fourth beta of Mac OS X 10.6.5 to developers
Google disputes Apple's indirect claims about Android activations
Apple's Jobs says 'onerous terms' kept Facebook ties out of Ping
Apple aiming to improve syncing, sorting of cloud-based content
Wall Street views new Apple TV as small step, not living room revolution
iTunes 10 now available for download
Amazon offers purchases of Fox and ABC shows for 99 cents
New Apple TV runs same custom A4 processor as iPhone 4, iPad
Apple's AirPlay to stream photos, video from iPhones to HDTVs
Apple's iOS 4.1 ships Sept. 8, will fix proximity sensor, add HDR photos [Ux2]
Apple's iPod classic survives another year, but sees no changes
Apple reveals new cloud-centric Apple TV for $99
Apple introduces iTunes 10 with Ping social music network
Apple unveils new iPod touch with Retina Display, forward-facing camera
Apple announces new iPod nano with multi-touch display
Apple adds buttons to new fourth-generation iPod shuffle
iOS 4.2 for iPad coming in November, adds wireless printing and Air Play
Live updates from Apple's September 1st Media Event
Apple posts live stream of special event keynote
New Apple TV, iPods to debut today, won't ship immediately - report
Intel CEO says he asked Steve Jobs' opinion on Infineon deal
Fox, ABC agree to give Apple 99-cent TV rentals
Videos emerge of possible iPod Touch, iPod Nano parts
Amazon working on streaming subscription video service
Apple to offer live video stream of Wednesday's keynote
New Apple TV with Netflix streaming to be unveiled Wednesday - report
Palm unveils webOS 2.0, SDK available to developers
Apple's new iPod nano to maintain price points, won't push out shuffle - sources
Mexico's Telcel claims iPhone 4 antenna hardware fix in the works

Advertisements







AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.