Another iPhone Vulnerability Found
July 19, 2007 | by Christopher Nickson
SPI Dynamics has uncovered a vulnerability in the iPhone's Safari browser that means calls can be tracked and redirected
You’d better watch out if you use your iPhone Safari browser to place calls. It turns out that there’s a vulnerability in it that can allow hackers to redirect the calls.
The problem was discovered by SPI Dynamics. The Safari browser on the iPhone had a touch screen feature that allows the user to call a number of a web site simply by tapping it. Hackers can install malware that redirects the call to an expensive 900 number, for instance. But there’s also the possibility of worse things.
“For example, an attacker could determine that a specific Web site visitor ‘Bob’ has called an embarrassing number such as an escort service,” Billy Hoffman of SPI wrote in a blog. “An attacker can also trick or force Bob into dialing any other telephone number without his consent, such [as] a 900-number owned by the attacker or an international number.”
Along with redirecting and tracking calls made by the user, the vulnerability means the phone can be manipulated to make a call without the user accepting the confirmation dialogue, can be placed in a loop of trying to make calls, so that turning the phone off is the only way to end it, and the phone can also be prevented from dialing.
For now, SPI is advising people not to use the feature on Safari. They reported the problem to Apple on July 6, and work is underway to find a fix.
Post Your Comment...Comments
Comment on this article
Please keep your comments relevant to this article. Email addresses are not displayed, they are only required to verify you are human.
When you submit your comment, an email will be sent to your email address with a confirmation link. Once you have clicked on that confirmation link your comment will be posted.
HTML is not allowed.

Be the first to comment on the article!