Most Popular in Apple
-
A Hands On Look at Safari 4's (Crashy) Eye Candy
-
Talkcast reminder: Oscar night show 10pm ET
-
FileMaker Pro 11 Brings Streamlined Database Creation With New Reporting and Collaboration Features
-
HTC lawsuit came after warning by Apple to handset makers
-
Verizon Viewing iPad as Opportunity to Push MiFi Service
-
TUAW How To: Downgrading your 3.1.3 iPhone to 3.1.2
-
GDC 2010: From concept to Top Paid with Unity iPhone
-
Yet Another Blurry and Fake iPhone 3G Summer 2009 Image (It's Iron Bar Time!)
-
Apple 'iKey' Places a Combination Lock on Your Wallet [Patents]
-
Black Swan brings Google Voice back to the iPhone without the App Store
Apple patching critical SMS vulnerability in iPhone OS
Security researcher Charlie Miller has revealed that Apple is working on a patch for a security flaw he identified in the iPhone's SMS implementation. The flaw can actually lead to arbitrary code execution, as he explained to Ars last month. Miller hasn't yet detailed the flaw, citing an agreement with Apple, though he and partner Vincenzo Iozzo plan to detail their discovery later this month at the Black Hat Security Conference in Las Vegas.
During a presentation at the SyScan security conference in Singapore, Miller explained that a vulnerability in the iPhone's handling of SMS messages makes it possible to send code instead of strictly text. Despite SMS's 140 byte size limitation, the iPhone can reassemble larger messages that are broken up to fit the limitation, which allows larger programs to be sent. The iPhone can be instructed to execute SMS data as code instead of text, and when it executes the code it does so with root privileges and without any interaction from the user.
Click here to read the rest of this article
More Stories in Arstechnica Apple News
- Code library gives homebrew iPod remotes chance for awesome
- etc: The fourth beta of iPhone OS 3.2 SDK adds references to triple-tap and "long press" gestures, but removes references to video chatting found in previous betas.
- Cellcos hoping to cash in on iPad with 3G/4G mobile hotspots
- Street Fighter IV: as good as you can expect on the iPhone
- HTC lawsuit came after warning by Apple to handset makers
- etc: Apparently the iTunes LP format was a concession from the iTunes DRM/price negotiations and not Apple's idea. This is why you're failing, music labels!
- etc: The EFF has published the iPhone developer agreement. Many of the stipulations are not new to most of us, but the EFF offers a number of criticisms on the agreement's limitations.
- FileMaker Pro goes to 11, admits people like spreadsheets
- etc: It's not official yet, but an insider claims that Tekken is coming to the iPhone OS. Time to re-live the '90s!
- Valve: full "Steam" ahead on Mac OS X with free syncing
Most Popular Stories
A Hands On Look at Safari 4's (Crashy) Eye Candy
Talkcast reminder: Oscar night show 10pm ET
FileMaker Pro 11 Brings Streamlined Database Creation With New Reporting and Collaboration Features
Ettus Research acquired by National Instruments
HTC lawsuit came after warning by Apple to handset makers
Verizon Viewing iPad as Opportunity to Push MiFi Service
TUAW How To: Downgrading your 3.1.3 iPhone to 3.1.2
GDC 2010: From concept to Top Paid with Unity iPhone
Yet Another Blurry and Fake iPhone 3G Summer 2009 Image (It's Iron Bar Time!)
Apple 'iKey' Places a Combination Lock on Your Wallet [Patents]