Apple iPhone
Researchers have uncovered more problems with the design and implementation of security on the iPhone

Remote control flaw found in iPhone

Attackers could take complete control of the platform

Iain Thomson

A team of security researchers in the US claims to have found a flaw in Apple's iPhone that could allow a hacker to take complete control of the device via Wi-Fi.

Independent Security Evaluators, headed by a former professor at Johns Hopkins University, found the hole last week, developed a patch and alerted Apple to the problem. 

Advertisement

"There are serious problems with the design and implementation of security on the iPhone," said the company in a Security Evaluation paper (PDF) on the flaw. 

"The most glaring is that all processes of interest run with administrative privileges. This implies that a compromise of any application gives an attacker full access to the device."

The exploit uses a web page with malware built in that can access the phone via the Safari browser.

This can either be used to force the phone to send personal information stored in its files or to take control of the device and make it place outgoing calls to other numbers.

"Unfortunately, once an iPhone application is breached by an attacker, very little prevents the attacker from obtaining complete control of the system," the team said.

"Additionally, no address randomisation is used in by the operating system. This means that each time a process runs, the stack, heap and executable code is located at precisely the same spot in memory. This helps attackers write reliable exploit code."

Experts have already warned that the phone may be as insecure as a PC because of its powerful operating system, and problems have already been reported with the dialler software

Matt Bancroft, vice president at mobile device management company Mformation, said: "All mobile phones are becoming more powerful, and the iPhone is really a sophisticated mini computer. 

"As we get more powerful mobile devices, it is inevitable that we will get more security issues and threats to mobile devices.

"The key is to manage the device once it is in the hands of the user. Being able to update or patch the security and applications over the air in an ever-changing environment is the way forward."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation