Most Popular in Apple
-
Localized Flipboard Content guides available for UK, Ireland, Australia and Canada
-
A fix for those "Pairing Record Missing" errors
-
You're the Pundit: iPad 3
-
Apple removes standard Mac OS X 10.7.3 download due to bugs, offers combined download instead
-
MPAA Sues LimeWire Back From The Dead
-
AirServer Lets You Push Airplay Audio To Your Apple Computer [Video]
-
Dev Juice: How do I autocomplete in Xcode 4?
-
Snow Leopard's 35 New Desktop Pictures Feature Nature, Fine Art and… Graffiti?
-
Apple tells newspapers: no free iPad edition for print subscribers
-
Apple Really Listening to Their Consumer
Apple patching critical SMS vulnerability in iPhone OS
Security researcher Charlie Miller has revealed that Apple is working on a patch for a security flaw he identified in the iPhone's SMS implementation. The flaw can actually lead to arbitrary code execution, as he explained to Ars last month. Miller hasn't yet detailed the flaw, citing an agreement with Apple, though he and partner Vincenzo Iozzo plan to detail their discovery later this month at the Black Hat Security Conference in Las Vegas.
During a presentation at the SyScan security conference in Singapore, Miller explained that a vulnerability in the iPhone's handling of SMS messages makes it possible to send code instead of strictly text. Despite SMS's 140 byte size limitation, the iPhone can reassemble larger messages that are broken up to fit the limitation, which allows larger programs to be sent. The iPhone can be instructed to execute SMS data as code instead of text, and when it executes the code it does so with root privileges and without any interaction from the user.
Click here to read the rest of this article
More Stories in Arstechnica Apple News
- Apple rules top three smartphone spots but loses new users to Android
- Another reason why Apple may be limiting Siri to iPhone 4S
- Poll Technica: should Apple more strictly police app ripoffs on the App Store?
- Week in Apple: post-Macworld|iWorld edition
- Apple updates iBooks Author EULA to clarify restriction on format, not content
- iPhone, iPad injunction lifted in Germany, but Apple still faces iCloud action
- Tim Cook: Apple donated $50 million to hospitals, $50 million to Project(RED)
- Apple now third largest mobile phone vendor as feature phones fade
- Etc: Xbox Live marketing head in the UK, Robin Burrowes, has reportedly been tapped to run Apple's App Store marketing in Europe.
- Problems with the OS X 10.7.3 update? Combo updater to the rescue
Most Popular Stories
Localized Flipboard Content guides available for UK, Ireland, Australia and Canada
A fix for those "Pairing Record Missing" errors
You're the Pundit: iPad 3
Apple removes standard Mac OS X 10.7.3 download due to bugs, offers combined download instead
MPAA Sues LimeWire Back From The Dead
This forum's font looks bad on my new installation
Scripting Issue
need to know if there are ftp connections in my machine
AirServer Lets You Push Airplay Audio To Your Apple Computer [Video]
Dev Juice: How do I autocomplete in Xcode 4?