Vulnerabilities / Threats
7/2/2009
03:13 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Apple Planning Fix For iPhone SMS Flaw

An SMS vulnerability in Apple's iPhone is slated for disclosure at the Black Hat conference later this month. Apple is reportedly rushing to get a fix ready.

Apple is reportedly working to fix an SMS message handling vulnerability in its iPhone that could be used by an attacker to run unauthorized code with full access to the device.

According to IDG News Service, Apple has been notified about the vulnerability and is working on a patch that's planned for release prior to the Black Hat USA security conference later this month.

Apple did not immediately respond to a request for comment. But iPhone vulnerabilities are not unheard of: The company's recent iPhone 3.0 software release included 46 fixes for security vulnerabilities.

At Black Hat, which runs from July 25-30 in Las Vegas, Charlie Miller, a security researcher with Independent Security Evaluators, plans to present information about the vulnerability.

Miller mentioned the vulnerability in an iPhone security presentation on Thursday at the SyScan security conference in Singapore, but declined to provide details, citing an agreement with Apple, IDG reports.

Miller was not immediately available to comment.

He plans to participate in two presentations at Black Hat: "Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone" and "Fuzzing the Phone in your Phone."

The former talk will explain how to inject unsigned code into an iPhone's process address space. The latter will explore how to inject SMS messages into iPhones, Android phones, and Windows Mobile devices using a technique called fuzzing.

Both this year and last, Miller has won Apple hardware at the CanSecWest security conference's Pwn2Own contest by exploiting previously unknown vulnerabilities in Apple's Safari Web browser.

Black Hat is owned by TechWeb, which also publishes InformationWeek.

InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0750
Published: 2015-05-22
The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitrary commands via crafted input to unspecified fields, aka Bug ID CSCut02786.

CVE-2012-1978
Published: 2015-05-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Agenda 2.2.8 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add an administrator via a request to auth/process.php, (2) delete an administrator via a request to auth/admi...

CVE-2015-0741
Published: 2015-05-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Prime Central for Hosted Collaboration Solution (PC4HCS) 10.6(1) and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut04596.

CVE-2015-0742
Published: 2015-05-21
The Protocol Independent Multicast (PIM) application in Cisco Adaptive Security Appliance (ASA) Software 9.2(0.0), 9.2(0.104), 9.2(3.1), 9.2(3.4), 9.3(1.105), 9.3(2.100), 9.4(0.115), 100.13(0.21), 100.13(20.3), 100.13(21.9), and 100.14(1.1) does not properly implement multicast-forwarding registrati...

CVE-2015-0746
Published: 2015-05-21
The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.