2009-08-01
Abstract
Patch released for critical SMS vulnerability.
Copyright © 2009 Virus Bulletin
Apple has released a patch for a critical SMS vulnerability in its iPhone following a description of the vulnerability and demonstration of a possible attack by researchers at the Black Hat security conference. Apple was first notified of the problem – which consists of a memory corruption issue in the decoding of SMS messages – in June. The vulnerability left iPhone users open to attack via receipt of a maliciously crafted SMS message which could lead to an unexpected service interruption or arbitrary code execution.
Details of the patch are provided on Apple’s support site (http://support.apple.com/kb/HT3754). At the VB2009 conference next month, Jason Matasano will discuss the risks and benefits of using the iPhone in a corporate environment, including examples of the potential malware implications (see http://www.virusbtn.com/conference/vb2009/programme for details).