Security firm claims first iPhone exploit
The popularity of the iPhone ensures that it’s going to be a target of unwelcome attentions, so the announcement this morning that a team of security researchers had allegedly discovered a vulnerability should not be shocking.
Independent Security Evaluators, the firm that did the investigation, claim to have found the hole in the iPhone’s version of Safari. It would allow for the execution of arbitrary code, run with administrative privileges. Such code can in theory do anything the iPhone can do, including sending text messages, stealing email passwords, or recording audio. The demo that ISE has concocted reads the SMS text log, the address book, the call history, and the voicemail data.
While this exploit should not be taken lightly, it’s important to note that it’s not in the wild: ISE has released a preliminary paper, with a full paper and presentation to be given at the BlackHat conference on August 2nd. They’ve notified Apple of the exploit along with a proposed fix. Also important to note is the potential attack vectors: since the vulnerability is in Safari, the user needs to click on a link or otherwise be directed to a malicious website, so it’s important to practice safe computing.
Category: News
ABOUT iPHONE CENTRAL
Get the latest news, reviews, and opinion about Apple's groundbreaking iPhone from the Apple experts at Macworld.
Want more information? Be sure to check out our complete iPhone coverage.
iPHONE QUESTIONS OR COMMENTS?
Send your iPhone thoughts:
via e-mail
via voicemail
and we may use them on the site.
BLOG ARCHIVE
- July 2008 (1)
- June 2008 (1)
- May 2008 (39)
- April 2008 (34)
- March 2008 (33)
- February 2008 (50)
- January 2008 (34)
- December 2007 (33)
- November 2007 (42)
- October 2007 (45)
- September 2007 (53)
- August 2007 (67)
- July 2007 (111)
- June 2007 (82)
CATEGORIES
- Accessories (39)
- AT&T (47)
- Hacking (31)
- Hardware (26)
- Musings (102)
- News (217)
- Reader Experiences (5)
- Reviews (51)
- Software (139)
- Tips & Troubleshooting (79)
- Videos (9)
- Wi-Fi (15)
