Major Security Flaw "Discovered In iPhone and iPad Software"





A security expert says he's found a flaw in iPhones and iPads running the latest iOS5 that could allow hackers to install apps to steal data, send text messages and destroy information.

He says he submitted a malicious app to Apple and it was approved for the App Store, getting through the company's strict vetting.
Charlie Miller, a researcher with Accuvant Labs who identified the problem, built a prototype malicious program to test the flaw. He said Apple's App Store failed to identify the malicious program, which made it past the security vetting process.
There is as yet no evidence that hackers have exploited the vulnerability in Apple's iOS software. But Miller said his test demonstrated that there could be real malware in the App Store.
"Until now you could just download everything from the App Store and not worry about it being malicious. Now you have no idea what an app might do," Miller said.
Miller said he proved his theory by building a stock-market monitoring tool, InstaStock, that was programmed to connect to his server once downloaded, and to then download whatever program he wants.
In 2009, Miller identified a bug in the iPhone that allowed hackers to gain control of the device.

Apple hasn't commented, but Miller says Cupertino is in the process of fixing the latest bug.

(Source: Reuters)


You can follow IJSMblog on Google+ Twitter and Facebook

Comments