Advertisement
Promo

Mobile devices Toolkit

Apple fixes iPhone call-hijack flaw

David Meyer ZDNet.co.uk

Published: 21 Nov 2008 13:19 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A serious security vulnerability has been discovered in the iPhone, but Apple said it has fixed the flaw in its latest firmware update for the handset.

On Thursday, the Fraunhofer Institute for Secure Information Technology (SIT) in Germany announced the flaw's discovery. The vulnerability could allow users to be tricked, via a link in an email, into opening webpages which then take over the iPhone's dialling capabilities, potentially calling a premium-rate number with the user being unable to stop the call.

"Today we published a small security bug present in the iPhone OS until version 2.1," wrote Fraunhofer SIT researcher Collin Mulliner on his blog on Thursday. "The bug is small but has [a] big impact in the way that it can be used to call arbitrary phone numbers from visiting a website."

On Friday, Apple released version 2.2 of the iPhone firmware. One of the security enhancements in the update, bearing the ID CVE-2008-4233, was aimed at stopping the flaw uncovered by Mulliner.

Apple described the bug thus: "If an application is launched via Safari while a call-approval dialogue is shown, the call will be placed. This may allow a maliciously crafted website to initiate a phone call without user interaction. Additionally, under certain circumstances it may be possible for a maliciously crafted website to block the user's ability to cancel dialling for a short period of time."

"This update addresses the issue by properly dismissing Safari's call-approval dialogue when an application is being launched via Safari," the security note read. "Credit to Collin Mulliner of Fraunhofer SIT for reporting this issue."

All in all, Apple addressed 12 vulnerabilities in version 2.2 of the iPhone firmware. Some of the flaws concerned the possibility of users being tricked into opening "maliciously crafted" Tiff or Excel files.

Another fix addressed the realisation by Apple that "the encryption level for PPTP VPN connections may be lower than expected", while one fix restricted emergency calls to a limited set of phone numbers — prior to that particular fix, an emergency call could be made to any number despite the device being locked.

The firmware update also included new features, such as the addition of Google Street View.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Lenovo repurchases mobile phone arm

Lenovo has bought back the mobile phone arm that it sold to a private equity firm at the start of 2008, the company said on Friday. The manufacturer sold Lenovo Mobile to the Hony... More

Post a comment

Jabra Stone Bluetooth headset

I don’t get on very well with Bluetooth headsets. But it is not a prejudice against them. I don’t get on well with those flat, saucer-like in-ear headphones either. My ears are just... More

Post a comment

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

Discussions

58358 58358

Don't forget the tools

Monday 30 November 2009, 7:15 PM

4 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters