Hot on HuffPost Tech:

See More Stories
AOL Tech

Apple Patches iPhone SMS Security Flaw

iPhone SMS Security Flaw DemoedA month after first announcing that the iPhone had a serious security flaw in how it handled text messages (and even longer still since it was first brought to Apple's attention), Charlie Miller at last publicly demonstrated the attack at yesterday's Black Hat Security Conference, and released a paper detailing how it is executed.

The flaw, which allows a hacker to hijack a phone by flooding it with invisible SMS control messages, isn't iPhone-specific. Windows Mobile and Android are also vulnerable, though Google patched the hole with its Cupcake update. The flaw is particularly worrisome since the only sign a user would see is a single text message with a lone box-like character. The rest of the control messages would not appear on the handset, but could shut down the phone entirely or even automatically forward the commands to other iPhones creating a vast mobile botnet.

Miller, and his partner Collin Mulliner, demonstrated the attack using an iPhone with OS 2.2.1, but the vulnerability was not patched with the 3.0 update. Technologizer backs up the the pair's claim, pointing out that the hole was not among the 46 security flaws plugged by the new OS update, and Elinor Mills, of CNET, claims the attack was informally demonstrated on her non-jailbroken iPhone running OS 3.0.

European cellular provider O2 told the BBC that Apple would be patching the flaw, and that an update would be available this weekend through iTunes, but Apple quickly (and without much fanfare) went ahead and pushed the update this afternoon, OS 3.0.1, to iTunes ahead of schedule (so go ahead and download it).

So, no need to panic, the patch is available now through iTunes (better late than never right?) and besides, the exploit is complex enough that it would likely take evildoers weeks to figure out how to leverage it for nefarious purposes. [From: CNET, Business Week, TUAW, and Mashable]

Tags: android, apple, botnet, charlie miller, CharlieMiller, hack, security, sms, text messaging, TextMessaging, top, windows mobile, WindowsMobile, winmo

Comments

1

Add your comments

Please keep your comments relevant to this blog entry. Email addresses are never displayed, but they are required to confirm your comments.

When you enter your name and email address, you'll be sent a link to confirm your comment, and a password. To leave another comment, just use that password.

To create a live link, simply type the URL (including http://) or email address and we will make it a live link for you. You can put up to 3 URLs in your comments. Line breaks and paragraphs are automatically converted — no need to use <p> or <br /> tags.

Coming soon

Thomas Houston

Editor in Chief

Amar Toor

Writer

Matthew Zuras

Design Editor

Leila Brillson

Features Editor

Terrence OBrien

Senior Blogger

Chad Mumm

Vid Guy

Meet the Team »

Get your Switched fix on the go with our free iPhone and iPod Touch app!

Chad Mumm

Reminds me of high school except these people are gauranteed to be cooler than me. http://t.co/3vVaSlz0

Chad Mumm

On The Verge episode 003… coming very soon.

Amar Toor

"was lying on his bed, smoking a cigarette and listening to Bachman-Turner Overdrive on the stereo he'd bought with his body shop earnings."

Paris

SINGLEHANDEDLY “@FRANCE24: Putin vows to boost Russian population http://t.co/fllBoJrc”