Apple bug lets hackers crash iPhones, iPads

The bug shows that attackers occasionally get the opportunity to damage Apple customers too

Bloomberg
Last Updated : Apr 24 2015 | 12:13 AM IST
Apple Inc's iOS operating system contains a bug that lets attackers crash iPhones and iPads within range of a wireless hotspot, security company Skycure said.

The devices' applications and even the entire base software shut down when served with manipulated SSL encryption certificates, Skycure CEO Adi Sharabani said in a phone interview. If hackers manage to force devices within range onto their own wireless network, they can effectively create a "no iOS zone," according to Skycure. "When their programmes crash, people tend to put this off as a quality issue," he said. "But it can be a serious vulnerability."

With Apple keeping tight control over its operating system's code and the applications that run on it, attackers targeting mobile devices have concentrated on the Android platform, which gives them more leeway for manipulation. Bloomberg

The bug shows that attackers occasionally get the opportunity to damage Apple customers too.

An Apple representative in London declined to comment.

The latest iOS version, the 8.3 released this month, fixed some of the vulnerabilities, while others could still be reproduced, Sharabani said. He declined to provide details so as to not give hackers instructions.

Reboot Cycles

Skycure, founded in 2012 by Sharabani and Chief Technology Officer Yair Amit, specializes in software that protects mobile devices from attacks via the airwaves. The company, which received $8 million last month from investors including Shasta Ventures, discovered in 2013 how hackers can force mobile users onto malicious wireless networks by using privileges normally reserved for mobile carriers.

Skycure researchers found the iOS bug while experimenting with various ways to connect devices to a network. When they brought in a new router and changed the wireless configuration, programs on devices running Apple software began crashing.

Hackers controlling the network that the device is on can also control the certificates that are normally being used to securely transfer data, and use them for a so-called "denial of service" attack. Since SSL encryption is used by iOS and almost all applications available in the app store, the vulnerability concerns a wide range of users.

In the worst case, the devices can be forced into reboot cycles that can only be broken if the customer moves out of range of the malicious network, Sharabani said. Users should make sure to upgrade their operating system soon, and be wary of using public local wireless networks, Skycure said.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Apr 24 2015 | 12:03 AM IST

Next Story