Site icon MacDailyNews

iPhone SMS bug to be attacked at Black Hat

“Apple has [less than] a day left to patch a bug in it’s [sic] iPhone software that could let hackers take over the iPhone, just by sending out and SMS (Short Message Service) message,” Robert McMillan reports for IDG News Service. “The bug was discovered by noted iPhone hacker Charlie Miller, who first talked about the issue at the SyScan conference in Singapore. At the time, he said he’d discovered a way to crash the iPhone via SMS, and that he thought that the crash could ultimately lead to working attack code.”

“Since, then he’s been working hard, and he now says he’s able to take over the iPhone with a series of malicious SMS messages. In an interview Tuesday, Miller said he will show how this can be done during a presentation at the Black Hat security conference in Las Vegas this Thursday with security researcher Collin Mulliner,” McMillan reports. “‘SMS is an incredible attack vector for mobile phones,’ said MIller, an analyst with Independent Security Evaluators. ‘All I need is your phone number. I don’t need you to click a link or anything.'”

McMillan reports, “Miller reported the flaw to Apple about six weeks ago, but iPhone’s maker has yet to release a patch for the issue. Apple representatives could not be reached for comment, but the company typically keeps quiet about software flaws until it releases a patch.”

Full article here.

Phillip Elmer-Dewitt reports for Fortune, “”The iPhone SMS bug is just one of a series that the researchers plan to reveal in their talk. They say they’ve also found a similar texting bug in Windows Mobile that allows complete remote control of Microsoft-based devices. Another pair of SMS bugs in the iPhone and Google’s Android phones would purportedly allow a hacker to knock a phone off its wireless network for about 10 seconds with a series of text messages. The trick could be repeated again and again to keep the user offline, Miller says.”

Full article here.

Exit mobile version