More

Researcher Charlie Miller Discovers iPhone App Security Bug

Charlie Miller Iphone

First Posted: 11/07/11 08:59 PM ET Updated: 11/08/11 10:23 AM ET

Mon Nov 7, 2011 8:03pm EST

(Reuters) - A software flaw in Apple Inc's iPhones and iPads may allow hackers to build apps that secretly install programs to steal data, send text messages or destroy information, according to an expert on Apple device security.

Charlie Miller, a researcher with Accuvant Labs who identified the problem, built a prototype malicious program to test the flaw. He said Apple's App Store failed to identify the malicious program, which made it past the security vetting process.

There is as yet no evidence that hackers have exploited the vulnerability in Apple's iOS software. But Miller said his test demonstrated that there could be real malware in the App Store.

"Until now you could just download everything from the App Store and not worry about it being malicious. Now you have no idea what an app might do," Miller said.

Miller said he proved his theory by building a stock-market monitoring tool, InstaStock, that was programed to connect to his server once downloaded, and to then download whatever program he wants.

(To see a YouTube video demonstration of the technique, go to here)

Apple did not respond to requests for comment.

Miller, who in 2009 identified a bug in the iPhone text-messaging system that allowed attackers to gain remote control over the devices, said that he had contacted the company about the vulnerability.

"They are in the process of fixing it," he said.

Miller is scheduled to present his detailed research at the SyScan '11 security conference in Taiwan next week

(here)

(Reporting by Jim Finkle; Editing by Gary Hill)

Copyright 2011 Thomson Reuters. Click for Restrictions

FOLLOW HUFFPOST TECH

Mon Nov 7, 2011 8:03pm EST (Reuters) - A software flaw in Apple Inc's iPhones and iPads may allow hackers to build apps that secretly install programs to steal data, send text messages or destr...
Mon Nov 7, 2011 8:03pm EST (Reuters) - A software flaw in Apple Inc's iPhones and iPads may allow hackers to build apps that secretly install programs to steal data, send text messages or destr...
Filed by Catharine Smith  | 
 
 
  • Comments
  • 202
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Bloggers
Recency  | 
Popularity
Page: 1 2 3 4  Next ›  Last »  (4 total)
01:55 PM on 11/09/2011
Apple's response was to pull his developer license.
photo
Mister Grumpy
An Angry American
12:53 PM on 11/09/2011
Got to still be better than the Android Marketplace where 90% of the Apps are garbage........
photo
HUFFPOST SUPER USER
Runey
anti-religionists, converge and amass
07:19 AM on 11/09/2011
That's why Apple implemented a blacklist.. so if it makes it past and they find out about it, they can basically ban it from running.
HUFFPOST SUPER USER
tarzan322
05:30 AM on 11/09/2011
The DOD doesn't use Apples for a reason. They are light years behind Windows on security because no one is writing viruses for Apples.
photo
Kendra Kroll
lose the worry...not your stuff
11:41 PM on 11/08/2011
that qualifies as a "whoops!"
08:12 PM on 11/08/2011
Apple is the DEVIL! I have always thought so.
HUFFPOST SUPER USER
lambdin1
What's this?
07:09 PM on 11/08/2011
What, me worry?!?!??? I gave up cell phones years ago. If you want me, write a letter!!!!!
11:02 PM on 11/08/2011
It looks like someone could email you too...
HUFFPOST SUPER USER
lambdin1
What's this?
08:12 AM on 11/09/2011
Yes, but I can ignor emails a lot easier. Like my junk mail that I recieve from advertisers.....
HUFFPOST SUPER USER
jflorish
06:59 PM on 11/08/2011
Doesn't bother me at all, appstore is still the safest out there and nothing is even close to it .......
photo
HUFFPOST SUPER USER
Scott Moguns
Retired LEO, Motorcycles, Guns and the Truth
04:57 PM on 11/08/2011
Apple is always wanting to get their product out to the customers without doing enough research on them
Not saying that their products can't be trusted just saying dollars over quality
photo
HUFFPOST SUPER USER
CaptainRenault
Here to keep an eye on the rascals.
04:43 PM on 11/08/2011
I'm so glad that I still have a phone that is not very bright.

^ ^
photo
HUFFPOST COMMUNITY MODERATOR
SoCalNick
Former 99er, Business Owner, Proud Veteran 101st
03:48 PM on 11/08/2011
Hey Apple.. KEEP UP THE GOOD WORK!

I just added a new Apple tech ( our first) 3 weeks ago.. he is SWAMPED!

Reality meets Marketing.

That is all
03:47 PM on 11/08/2011
This writer leaves out a huge part...Apple banned Charlie Miller from the developers project right after he made this announcement. Appearently he was doing the job to good and found the flaws Apple denied ever existed so they had to get rid of the guy for being honest and truthful and helping show their security issues they claim they have never had lol.. You show apple they are worng and back it with proof they get rid of you. Gotta love a company that is more worried about covering its lies then its customers.
photo
HUFFPOST SUPER USER
CaptainRenault
Here to keep an eye on the rascals.
04:44 PM on 11/08/2011
Very much like Microsoft in this regard.

^ ^
08:01 PM on 11/15/2011
Oh I hadn't been aware of this happening. I would be interested in learning more though. Can you please give me a link to a story where Microsoft openl;y hired a hacker to find their flaws but then fired him when he found too many too quick. id be interested in reading it if its true......Ill wait for the link reply..Thanks
photo
HUFFPOST COMMUNITY MODERATOR
SoCalNick
Former 99er, Business Owner, Proud Veteran 101st
03:24 PM on 11/08/2011
Be Careful what you wish for Apple.

It has been a FACT for Decades that it was Apples TINY market share that kept it relatively safe from these types of programs NOT its security or superiority .

Now that Apple has grown..although not a much as they like to trumpet every day they have gotten attention from the more serious hackers and miners.

This is a numbers game and always has been... Go after the biggest and get the most results.

Apple may now be in the 10% range so now it will be looked at.

Always has been this way... Welcome to the world of relevancy Apple.

That is all
HUFFPOST SUPER USER
juanjo
03:39 PM on 11/08/2011
So true. So amusing in a cynically ironic way. I have been warning Apple maniacs about this for years whenever they smugly informed me of how they did not need to worry about things like worms, trojans etc.
photo
HUFFPOST SUPER USER
Runey
anti-religionists, converge and amass
07:25 AM on 11/09/2011
That's half true. The system IS Unix based, after all.
photo
HUFFPOST SUPER USER
Channa
Everyone is entitled to my opinion.
12:56 PM on 11/08/2011
Apple needs to hire this guy!
01:29 PM on 11/08/2011
you would think but they would rather not have anyone expose how crappy the software is ... so they stop him from being a developer

http://www.theinquirer.net/inquirer/news/2123402/apple-bars-security-researcher-unsigned-code-test
03:48 PM on 11/08/2011
I just made a comment above saying the article left the part out where apple ban the guy from doing this work as a devloper when he proved another security flaw to apple lol Youd think Apple would care about its customers but obviously its more about protecting their image and lies lol
12:42 PM on 11/08/2011
The only insidious product is the iCloud which after initiating lost 75% of my contacts. The genius bar told me "it's not perfect." I say "then don't release it!"