Most Popular in Apple
-
Billboard nominates music app awards
-
Apple releases preview 3 of Xcode 4
-
Facebook Blocked Ping's API Access Because Apple Didn't Have Authorization To Use It [Unconfirmed]
-
iOS 4.1 Gold Master Now Available To iPhone Developers [Apple]
-
Confusion Over Facebook's Brief Appearance in Ping for iTunes
-
A Simple Way to Attach Your iPad to Your Walls [Ipad]
-
Steve Jobs: Facebook had "onerous terms" for Ping
-
Walkman Outsold iPod in Japan During August [Apple]
-
Old AppleTVs Won't Get Netflix, Or Any of the New Software [Appletv]
-
Postage Stamps Go High-Tech With QR Code-Like Stamp Readable by Apps [IPhone Apps]
Apple patching critical SMS vulnerability in iPhone OS
Security researcher Charlie Miller has revealed that Apple is working on a patch for a security flaw he identified in the iPhone's SMS implementation. The flaw can actually lead to arbitrary code execution, as he explained to Ars last month. Miller hasn't yet detailed the flaw, citing an agreement with Apple, though he and partner Vincenzo Iozzo plan to detail their discovery later this month at the Black Hat Security Conference in Las Vegas.
During a presentation at the SyScan security conference in Singapore, Miller explained that a vulnerability in the iPhone's handling of SMS messages makes it possible to send code instead of strictly text. Despite SMS's 140 byte size limitation, the iPhone can reassemble larger messages that are broken up to fit the limitation, which allows larger programs to be sent. The iPhone can be instructed to execute SMS data as code instead of text, and when it executes the code it does so with root privileges and without any interaction from the user.
Click here to read the rest of this article
More Stories in Arstechnica Apple News
- Etc: Apple has revamped its movie trailers page to now offer showtimes, along with a map. It can automatically detect your location too, so no input necessary.
- iTunes 10 hands-on: snappier performance, questionable UI choices
- Etc: Apple has posted a page teasing the upcoming features of iOS 4.2 for iPad, including the wireless printing and AirPlay compatibility. Just ship it already!
- Etc: Spam has already started to pop up on Apple's new Ping social network. There are built-in tools to report it, but can't we have just one spam-free online service?
- Hands-on: Twitter officially comes to the iPad
- Apple's trouble with TV
- Hands-on with iTunes Ping, sans Facebook Connect
- iTunes 10 adds "Ping" social network, TV rentals, AirPlay
- Hands-on photos, observations of new iPods, Apple TV
- No longer a hobby? $99 Apple TV drops storage, integrates Netflix
Most Popular Stories
Billboard nominates music app awards
Apple releases preview 3 of Xcode 4
netstat showing lots of errors
Facebook Blocked Ping's API Access Because Apple Didn't Have Authorization To Use It [Unconfirmed]
iOS 4.1 Gold Master Now Available To iPhone Developers [Apple]
Confusion Over Facebook's Brief Appearance in Ping for iTunes
A Tale of Two Moderation Models
A Simple Way to Attach Your iPad to Your Walls [Ipad]
Steve Jobs: Facebook had "onerous terms" for Ping
Walkman Outsold iPod in Japan During August [Apple]