Advertisement
Promo

Mobile devices Toolkit

Apple fixes iPhone call-hijack flaw

David Meyer ZDNet.co.uk

Published: 21 Nov 2008 13:19 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A serious security vulnerability has been discovered in the iPhone, but Apple said it has fixed the flaw in its latest firmware update for the handset.

On Thursday, the Fraunhofer Institute for Secure Information Technology (SIT) in Germany announced the flaw's discovery. The vulnerability could allow users to be tricked, via a link in an email, into opening webpages which then take over the iPhone's dialling capabilities, potentially calling a premium-rate number with the user being unable to stop the call.

"Today we published a small security bug present in the iPhone OS until version 2.1," wrote Fraunhofer SIT researcher Collin Mulliner on his blog on Thursday. "The bug is small but has [a] big impact in the way that it can be used to call arbitrary phone numbers from visiting a website."

On Friday, Apple released version 2.2 of the iPhone firmware. One of the security enhancements in the update, bearing the ID CVE-2008-4233, was aimed at stopping the flaw uncovered by Mulliner.

Apple described the bug thus: "If an application is launched via Safari while a call-approval dialogue is shown, the call will be placed. This may allow a maliciously crafted website to initiate a phone call without user interaction. Additionally, under certain circumstances it may be possible for a maliciously crafted website to block the user's ability to cancel dialling for a short period of time."

"This update addresses the issue by properly dismissing Safari's call-approval dialogue when an application is being launched via Safari," the security note read. "Credit to Collin Mulliner of Fraunhofer SIT for reporting this issue."

All in all, Apple addressed 12 vulnerabilities in version 2.2 of the iPhone firmware. Some of the flaws concerned the possibility of users being tricked into opening "maliciously crafted" Tiff or Excel files.

Another fix addressed the realisation by Apple that "the encryption level for PPTP VPN connections may be lower than expected", while one fix restricted emergency calls to a limited set of phone numbers — prior to that particular fix, an emergency call could be made to any number despite the device being locked.

The firmware update also included new features, such as the addition of Google Street View.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Mobile business social network tools c...

The APIs that RIM is opening up for the BlackBerry platform leapfrog what’s available on other mobile platforms, with free push updates, unified advertising and payment options and... More

Post a comment

The Crabble stand for your phone

Sometimes something comes along that is so simple yet so very useful that you can’t believe you didn’t think of it first. The Crabble is one such object. Once upon a time smartphones... More

Post a comment

Taking Out the Skype Garbage

I don't write much about Skype any more, mostly because I find the entire company, its product and the situations surrounding it totally disgusting. However, a couple of things have... More

2 comments

Discussions

ator1940 ator1940

Open source code

Thursday 12 November 2009, 3:57 AM

3 comments
CA CA

DNA details of innocent will be kept f...

Wednesday 11 November 2009, 10:46 PM

2 comments
Tezzer Tezzer

Weak

Wednesday 11 November 2009, 10:43 PM

3 comments
CA CA

But still...

Wednesday 11 November 2009, 9:30 PM

1 comment

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters