SMARTPHONES

Apple patching serious SMS vulnerability on iPhone

Jul 02, 2009 11:57 pm | IDG News Service
by Sumner Lemon

Due to a reporting error, the story "Apple patching serious SMS vulnerability on iPhone," posted on July 2, incorrectly reported that Apple is fixing a flaw in the way the iPhone handles SMS messages. There is no confirmation that such a fix is in the works, although the researcher who found the bug hopes it will be fixed. The title of the story along with paragraphs 1 and 6 have been changed to reflect this.

In addition, the story has been clarified to stress the theoretical nature of attacks taking advantage of an SMS flaw on the iPhone, with changes made to paragraphs 2, 4 and 5 to make this more clear. The story has been changed on the wire and the title and affected paragraphs now read:

Apple may patch serious SMS vulnerability on iPhone

Apple may be working to fix an iPhone vulnerability that could possibly allow an attacker to remotely install and run unsigned software code with root access to the phone.

The theoretical attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service), said security researcher Charlie Miller, during a presentation at the SyScan conference in Singapore on Thursday. He didn't provide a detailed technical description of the SMS vulnerability.

An SMS flaw might allow an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. In Miller’s case, it appears he used the flaw he found to remotely crash an iPhone, a sign that a more serious attack might be possible.

If so, the malicious code could theoretically include commands to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet, Miller said

Miller reported the vulnerability to Apple, hoping it will get fixed. He plans to discuss the flaw further during a presentation at the Black Hat USA conference in Las Vegas.