Vulnerabilities / Threats
03:13 PM
Connect Directly

Apple Planning Fix For iPhone SMS Flaw

An SMS vulnerability in Apple's iPhone is slated for disclosure at the Black Hat conference later this month. Apple is reportedly rushing to get a fix ready.

Apple is reportedly working to fix an SMS message handling vulnerability in its iPhone that could be used by an attacker to run unauthorized code with full access to the device.

According to IDG News Service, Apple has been notified about the vulnerability and is working on a patch that's planned for release prior to the Black Hat USA security conference later this month.

Apple did not immediately respond to a request for comment. But iPhone vulnerabilities are not unheard of: The company's recent iPhone 3.0 software release included 46 fixes for security vulnerabilities.

At Black Hat, which runs from July 25-30 in Las Vegas, Charlie Miller, a security researcher with Independent Security Evaluators, plans to present information about the vulnerability.

Miller mentioned the vulnerability in an iPhone security presentation on Thursday at the SyScan security conference in Singapore, but declined to provide details, citing an agreement with Apple, IDG reports.

Miller was not immediately available to comment.

He plans to participate in two presentations at Black Hat: "Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone" and "Fuzzing the Phone in your Phone."

The former talk will explain how to inject unsigned code into an iPhone's process address space. The latter will explore how to inject SMS messages into iPhones, Android phones, and Windows Mobile devices using a technique called fuzzing.

Both this year and last, Miller has won Apple hardware at the CanSecWest security conference's Pwn2Own contest by exploiting previously unknown vulnerabilities in Apple's Safari Web browser.

Black Hat is owned by TechWeb, which also publishes InformationWeek.

InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-08
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

Published: 2015-10-08
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequently bypass intended login restrictions or obtain sensitive information, by leveraging certain group-administration privile...

Published: 2015-10-08
The REST interface in Cisco Unified Communications Manager IM and Presence Service 11.5(1) allows remote attackers to cause a denial of service (SIP proxy service restart) via a crafted HTTP request, aka Bug ID CSCuw31632.

Published: 2015-10-08
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0), 7.3(101.0), and 7.4(1.19) allow remote attackers to cause a denial of service (device outage) by sending malformed 802.11i management data to a managed access point, aka Bug ID CSCub65236.

Published: 2015-10-06
libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 21335999.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.