Most Popular in Apple
-
A fix for those "Pairing Record Missing" errors
-
Coolest keyboard ever
-
Apple Reaches Out to Cupertino Neighbors Regarding 'Campus 2' Plans
-
Presidents Obama, Clinton pay tribute to Steve Jobs at Webbys
-
Daily Update for May 21, 2012
-
Amtrak conductors to "punch your ticket" using iPhones
-
Review & Swatches: MAC 'Lovelorn' Lipstick
-
Daily iPhone App: Inertia: Escape Velocity HD
-
What If Tony Stark Designed His Iron Man Suit in MacPaint?
-
Need new contact program for Mac
Apple patching critical SMS vulnerability in iPhone OS
Security researcher Charlie Miller has revealed that Apple is working on a patch for a security flaw he identified in the iPhone's SMS implementation. The flaw can actually lead to arbitrary code execution, as he explained to Ars last month. Miller hasn't yet detailed the flaw, citing an agreement with Apple, though he and partner Vincenzo Iozzo plan to detail their discovery later this month at the Black Hat Security Conference in Las Vegas.
During a presentation at the SyScan security conference in Singapore, Miller explained that a vulnerability in the iPhone's handling of SMS messages makes it possible to send code instead of strictly text. Despite SMS's 140 byte size limitation, the iPhone can reassemble larger messages that are broken up to fit the limitation, which allows larger programs to be sent. The iPhone can be instructed to execute SMS data as code instead of text, and when it executes the code it does so with root privileges and without any interaction from the user.
Click here to read the rest of this article
More Stories in Arstechnica Apple News
- Etc: The iPhone 4S launches on three new regional carriers on May 18 with a $50 discount: Bluegrass Cellular, Golden State Cellular, and Nex-Tech Wireless.
- Apple, Samsung cut some patent claims to keep July 30 trial date in US
- iOS 5.1.1 patches URL spoofing flaw, two other security vulnerabilities
- Etc: Apple engineers are reportedly investigating how to add multi-user support to the iPad, though there's no guarantee it will happen as of yet.
- OS X plain text password flaw has been around for 3 months and counting
- Apple improves AirPlay playback, iPad network switching, HDR with iOS 5.1.1
- Free 20GB cloud storage for MobileMe subscribers extended to Sept. 30
- Etc: AT&T CEO Randall Stephenson claims to regret offering unlimited data to iPhone users, adding that he's losing sleep over free messaging services (like iMessage) that take away from AT&T's business.
- Not-Horrible iPad Cases: a round-up of the best
- Week in Apple: Mastered for iTunes, RubyMotion, and Willy Wonka Jobs
Most Popular Stories
A fix for those "Pairing Record Missing" errors
Coolest keyboard ever
Apple Reaches Out to Cupertino Neighbors Regarding 'Campus 2' Plans
Presidents Obama, Clinton pay tribute to Steve Jobs at Webbys
errpt SYSTEM SHUTDOWN BY USER
Clear command help & alias
Daily Update for May 21, 2012
SDD SDDPCM MPIO lspath Jargon
Amtrak conductors to "punch your ticket" using iPhones
sppp0 interface in solaris 10