On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

July 3rd, 2008

Apple caught neglecting iPhone security

Posted by Ryan Naraine @ 11:37 am

Categories: Apple, Arbitrary Code Execution, Browsers, Data theft, Exploit code, Metasploit, Mobile (In)Security, Open source, Patch Watch, Pen testing, Vulnerability research, Wi-Fi security

Tags: Ryan Naraine

Apple neglecting iPhone security?If you’re waiting on iPhone 2 to standardize your business on the awesome new device (yeah, I’ll be on line to buy one), you might want to pay attention to the conspicuous absence of iPhone security patches over the last four months.

As WaPo’s Brian Krebs reports, the iPhone runs a stripped down version of Mac OS X but, even though OS X security updates are coming fast and furious, the iPhone has been neglected.

This means that there are multiple serious iPhone code execution flaws — including the CanSecWest Safari contest bug — that remains unpatched.

Krebs writes:

In seeking confirmation of this, I spoke recently with Charlie Miller, one of the foremost OS X and iPhone security researchers. Miller confirmed that the iPhone updater tells users that if they have version 1.1.4 installed then they are running the most current version. The problem is that this update does not include fixes for a slew of security holes in the Safari Web browser and other OS X components upon which the iPhone relies heavily.

“Apple should either update their software like they do with the core operating system, or otherwise don’t advertise the fact that the iPhone checks for updates every week,” Miller said. “Right now, an iPhone user is going to think they’re up-to-date because there’s no patch available, but the reality is that users are only as secure as they were back in February.”

Even more worrisome, Miller has created a tool to exploit the Safari vulnerability on an iPhone.

Using the exploit, an attacker who convinces an iPhone user to click on a malicious link could steal the victim’s call records or contacts, send text messages or read the user’s sent and received messages, and make outgoing calls, among other things.

There’s also an iPhone zero-day floating around out there.

So, if you love your iPhone like I do,  consider sending Apple a note (<product-security@apple.com>) and let them know that this neglect is unacceptable.

* Image source:  oskay’s Flickr photostream (Creative Commons 2.0).

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 24 Talkback(s)
The Three Stooges at ZDNet
Could three guys be more blatantly biased and dishonest? I think not. Windows has been vulnerable to attack since day one. PC's are more vulnerable to attack then Macs mostly in part due to market sha... (Read the rest)
Posted by: 3dtodd Posted on: 07/25/08 You are currently: a Guest | | Terms of Use
Apple doesn't really care.  daMan25 | 07/03/08
If these still exist after the 2.0 update  frgough | 07/03/08
How long is long enough?  NonZealot | 07/03/08
Ugh...  nmcfeters | 07/03/08
Don't you think...  msalzberg | 07/03/08
true dat!  1tl | 07/04/08
That's the most ridiculous statement ever made  nmcfeters | 07/03/08
Dialing Down  Harry Bardal | 07/03/08
Only 7 years?  NonZealot | 07/03/08
Excellent  Harry Bardal | 07/03/08
I agree, but.......  daMan25 | 07/04/08
OK, Define consequence free.  Suicida| | 07/04/08
The update is coming out in 8 days.  frgough | 07/03/08
Why doesn't Apple release it now if it is ready?  NonZealot | 07/03/08
RE: Apple caught neglecting iPhone security  Telix | 07/03/08
He's admitted that he's never...  msalzberg | 07/03/08
I can scroll up!  beoz | 07/03/08
RE: Apple caught neglecting iPhone security  1macgeek | 07/03/08
I'm glad my phone isn't being targeted by useless exploits like this  NonZealot | 07/03/08
How do you know your phone is safer? (nt).  A Grain of Salt | 07/03/08
I Agree....  Brich | 07/04/08
Define Useless  1macgeek | 07/04/08
RE: Apple caught neglecting iPhone security  anirudhsharma | 07/05/08
The Three Stooges at ZDNet  3dtodd | 07/25/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads