An SMS vulnerability in Apple's iPhone is slated for disclosure at the Black Hat conference later this month. Apple is reportedly rushing to get a fix ready.

Thomas Claburn, Editor at Large, Enterprise Mobility

July 2, 2009

1 Min Read

Apple is reportedly working to fix an SMS message handling vulnerability in its iPhone that could be used by an attacker to run unauthorized code with full access to the device.

According to IDG News Service, Apple has been notified about the vulnerability and is working on a patch that's planned for release prior to the Black Hat USA security conference later this month.

Apple did not immediately respond to a request for comment. But iPhone vulnerabilities are not unheard of: The company's recent iPhone 3.0 software release included 46 fixes for security vulnerabilities.

At Black Hat, which runs from July 25-30 in Las Vegas, Charlie Miller, a security researcher with Independent Security Evaluators, plans to present information about the vulnerability.

Miller mentioned the vulnerability in an iPhone security presentation on Thursday at the SyScan security conference in Singapore, but declined to provide details, citing an agreement with Apple, IDG reports.

Miller was not immediately available to comment.

He plans to participate in two presentations at Black Hat: "Post Exploitation Bliss: Loading Meterpreter on a Factory iPhone" and "Fuzzing the Phone in your Phone."

The former talk will explain how to inject unsigned code into an iPhone's process address space. The latter will explore how to inject SMS messages into iPhones, Android phones, and Windows Mobile devices using a technique called fuzzing.

Both this year and last, Miller has won Apple hardware at the CanSecWest security conference's Pwn2Own contest by exploiting previously unknown vulnerabilities in Apple's Safari Web browser.

Black Hat is owned by TechWeb, which also publishes InformationWeek.

InformationWeek has published an in-depth report on smartphone security. Download the report here (registration required).

About the Author(s)

Thomas Claburn

Editor at Large, Enterprise Mobility

Thomas Claburn has been writing about business and technology since 1996, for publications such as New Architect, PC Computing, InformationWeek, Salon, Wired, and Ziff Davis Smart Business. Before that, he worked in film and television, having earned a not particularly useful master's degree in film production. He wrote the original treatment for 3DO's Killing Time, a short story that appeared in On Spec, and the screenplay for an independent film called The Hanged Man, which he would later direct. He's the author of a science fiction novel, Reflecting Fires, and a sadly neglected blog, Lot 49. His iPhone game, Blocfall, is available through the iTunes App Store. His wife is a talented jazz singer; he does not sing, which is for the best.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights