|
|
|

Apple Fixes iPhone SMS Vulnerability Highlighted at Black Hat
By: Brian Prince
2009-07-31
Article Rating:    / 1
There are 1 user comments on this Network Security & Hardware story.
Apple has swatted a bug in the iPhone that security researchers Charlie Miller and Collin Mulliner spotlighted at the Black Hat security conference in Las Vegas.Apple has fixed the iPhone vulnerability highlighted at the Black Hat security conference yesterday.
The update plugged a
memory corruption issue in the decoding of SMS messages that could be
exploited to remotely execute code on the phone. The vulnerability was
put in the spotlight after a presentation by researchers Charlie Miller
and Collin Mulliner.
The two demonstrated how hackers could use the iPhones texting
capability to attack users, sending messages to victims in an
attempt to compromise the phone.
In a statement,
Apple officials said that no one has been able to use the vulnerability
to take control of the iPhone and gain access to personal
information.
"We appreciate
the information provided to us about SMS vulnerabilities that affect
several mobile phone platforms, a spokesman said. This morning, less
than 24 hours after a demonstration of this exploit, we've issued a
free software update that eliminates the vulnerability from the
iPhone.
A paper Miller and Mulliner published on the situation in June is available here.
|
|
x}r㶲s\@♵M=ҔlcؖgRJEĘ"H%g~u~|.g&-`h
F; IMל۔O]sSãw$5]2I=*rdz&9%GjL7 R}f]S k kL|Nშ:':@.Pk< Z535ԗoˏ~e0.ڎIQ6*6Oմ,lZ P8$ˑh]
!QQ;ߵ-m:
\'|w*UnSp{ca_ʞz5EhDԸ#|x\'gώ0{lY}@|ݑ|Y#Xo:QA3MuL֟CԿ($fʀ[8QKjF=Ķ|hG'tqr_Yoסn=wdo&A0[b#6fJۆؼ?0H&5\O, E&sؗCYͼAeȆ}{RM*QR,הby/^[̿XYpoz_{JY4E].;gW9(֝[pnKVj0n{'Owq@α{A~A7"
DT)Jj\(MDCajLx:~Hs|T㍒~7jy%R+
iɥzd$Y3)N,ԐX;~K~2/NM퓳NlM,O!R42V,]?#;ˠzqsںy\7=rڽ&Iٝ{N4ps
Z_Zz<-/x_6l
Muô|WVK5IͽGb=jI o]}<>$7Yn[䗳90omYn_H.a(7f`XӀ7? eR2\ML9X@.@ש#04ǯiVj5V0z[PĿ E/<@'L[w P3Z$923=Pru&Sk~ $M]sb.L2o<|)6`I˪2TI0%mQa:]R$y3DDȝ g/3/r.i } h8yWҽT7ws
iغT49;?]/7+De,Ⱥ
s5-wfzˬ;\g8m7-һ^5?A*)5>'4d}t>(>hƋCriYnL,rӇtu4A.~{ݣn]?'tnYXŞ*LRVi50CA6]LR}>t9qPhQ0<szL,)σ5[ӽ:?@6xBe^~}̢1O [>=Ś閭-L<ģܠ~QN\QoD-2(%E2 EEKi@( $h5ar./lbo(w$]I+Tbz"ҶBIҗRX){TKh+K@f:34YIJM
X*ȉ#m"09X
,'Z
X%Z)m2*COzgؕJVȊ*jOL}C:as#O̡GLx}GEڟPc^o2,XhqOc6s{D[ q3ԛm)}Pdd/5SGZdLAuϝ2h Jd@`Wv.َgK4'*Jr_NM)Hj`~)n^ßݴ#>d .z:H(p0ѿyĞnv(4UʝWRy'g|))<k1!I/tzS\&)9Aw
Uw誟Fi'OZdxh6 V7v/:At ~ޮLR[kYFފy˾0p
WZڄ"b b7{\X3-#
l,.h?4W0Ԓd6\{8`OEMĽ~[*+n#7~4EiZ\-}s4
9P8wSJ$l%KW)w =hZz
F<> 7=`z:N #0
l1ZJ[Y,,aThjU֨z
of %lDo1c@u\Xb:tgya?_YTN۫kʮtٔүhvp
;fkxF3fԑeSPݷ&٤ bZk;P0KJAUc/csMD@knV2&Gmܑk}6fuEƱ4g3t%ra9 p 9& zqHe /Za秺
Cؚy~Scs;!䚻 !`Tcf:uV*ی;$!UTmDq"
֚p성 .c"}=v0$t`n̂_HE"}[pp\U.(L0:Kr2b,X[TB$⦼6t߂bIt`1:C5z_{=2dB4^Uf<{LRTj%F0:*GERWt~G OgԀA_ԁdˬ7?ڀPz;gn%Wߙ#[aeF]H?`7. _k軏hB1F}l#e{X~\U4Uud
XZ 0 (E{耰⢉!H{+4pý225\ZS:ٝ'(R~p;>mQI4YZH]ŤX
LkʚQ rCԃ3~Sb_@URTʞwZu^ߜ]pHA`!
Нv;#ؐCKAk1o@q>:(T7gmE{^ac7U[o&F)-ғU4
OB|>675/JAd[|8.S7poj-[zEP7Oƹ7<sƃ~wBy@*F_H_-ϺBN7xlxPym/i_2LFdT~!\yRflҡi22˓O~VA70p[c?֍Lnb*r12~
z:i0-aZ`O- quhՂ|ͧ zw\2ZVj,aڝNC7E$9`ܘGpXH;}'gЍU?F8Z7pթr VgPWtY/sOYy"
24A̙!YT<F|jb"MٸE5`|l'Ge7M3*P7n-˕2~ |