Serious SMS Vulnerability discovered on iPhone OS3.0

Jul
2

Apple is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone.

The attack, which has not been described in detail, works when the attacker sends the victim an SMS that could cause the phone to run malicious code or programs without the phone operator’s permission.

The SMS vulnerability allows an attacker to run software code on the phone that is sent by SMS over a mobile operator’s network. The malicious code could include commands to monitor the location of the phone using GPS, turn on the phone’s microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet.

The person who discovered the vulnerability, Charlie Miller, has been working with Apple and he will not discuss in detail the vulnerability until Apple has released the patch for the exploit.

Source: ComputerWorld

  • Share/Bookmark
 

Leave a Reply