Apple patching serious SMS vulnerability on iPhone
Apple Inc. is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone.
The attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service), said security researcher Charlie Miller, during a presentation at the SyScan conference in Singapore on Thursday. He didn't provide a detailed description of the SMS vulnerability, citing an agreement with Apple. Miller is an authority on Mac OS X security, and is a co-author of The Mac Hacker's Handbook.
The SMS vulnerability allows an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. The malicious code could include commands to monitor the location of the phone using GPS technology, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial-of-service attack or a botnet, Miller said
