Safari exploit gives hackers full control over iPhones and possibly PCs and Macs
Oops, researchers just unveiled a pretty serious security vulnerability in the iPhone. More specifically, it's Apple's Safari web browser which exhibits the vulnerability. Researchers at Independent Security Evaluators have used the vulnerability to take malicious control of the iPhone from rogue websites loaded with the exploit. Once in, researchers have full administrative access over the phone allowing them to listen in on room audio or snatch the SMS log, address book, call history, email passwords and more -- we're talking full access to your phone. Researchers note that the only way to stay safe is to check those URLs and only visit sites that you trust (which isn't very reassuring) and "may or may not be exploitable" from Mac and PC versions of Safari -- the same vulnerability exists only they haven't written the proof-of-concept exploit to test it yet. Apple has been notified of the vulnerability and a proposed fix with full public disclosure coming at the BlackHat conference on August 2nd. You listening InfoSec Sellout? That's how you report a bug. Check the exploit in video form after the break. [Via MacRumors]












Reader Comments (Page 1 of 1)
Max Waterman @ Jul 23rd 2007 4:10AM
I wonder if the exploit is also in Nokia's S60/3rd web browser (since it uses the same base code as Safari)...lots of them 'out there' too.
Gerhard @ Jul 23rd 2007 4:37AM
Nokia doesn't use the the Safari BASED browser to as the vehicle to install extra stuff. Should be safe.
Jamar @ Jul 23rd 2007 6:53AM
This could also be used to locate your phone in case you lose it, or at the very least recover everything from it.
If this could only be used to execute third-party programs... Web applications can only do so much.
pkassaie @ Jul 31st 2007 10:42AM
The iPhone does not have GPS, no positive spin there either. If they can fix the bug "hoorah", if this is a sign of things to come "boo".
Jamar @ Jul 23rd 2007 5:00PM
Note the "full access" to the iPhone- at the very least you can recover everything from it and wipe it clean.