home
December 8, 2009
Posted by Dan

A Swiss iPhone developer has published research that indicates that security vulnerabilities affecting the iPhone are not limited to jailbroken iPhones. Developer Nicholas Seriot has created a proof of concept app called SpyPhone as a demonstration of how Apple’s own APIs could be misused to read or edit a user’s address book or gain access to a user’s web surfing history or recent location information.

For such attacks to succeed, a malicious application would still need to get past Apple’s stringent App Store approval process to be available for non-jailbroken iPhones, however this is not outside of the realm of possibility as such an app would not require the use of any exploits or third-party APIs, and the spyware portion could be hidden by delayed activation or an encrypted payload.

Seriot detailed these potential iPhone privacy risks in a talk he delivered in Geneva on Wednesday, during which he also outlined possible defense strategies, suggesting that Apple should design the iPhone OS to require users to authorize read or read-write access by iPhone applications to potentially sensitive on-device information such as the Address Book, add firewall functionality to the device and ensure the keyboard cache is not as readily available to third-party applications.

- source: theregister.co.uk

Share This With...
  • Facebook
  • Digg
  • Twitter
  • RSS
  • Slashdot
  • Technorati
  • del.icio.us
  • Reddit
  • Blogosphere News
  • HackerNews
  • StumbleUpon
  • Google Bookmarks
  • email

One Response to “Possible Security Leak in Non-Jailbroken iPhone Apps”

  1. [...] phone was safe from security leaks, think again – Swedish developers have created an app which deliberately pulls contact info and recent location data, all using Apple APIs.. Needless to say, if such an app passed the App Store approval process there [...]

Leave a Reply

Follow Dashhacks:
iPhone-Hacks RSS FeedJoin the Dashhacks Fan Club on FacebookFollow Dashhacks on Twitter

Recent Posts

Poster: chinz

Tue Aug 31, 2010 3:08 pm


Poster: paulsiew31

Tue Aug 31, 2010 1:42 pm


Poster: oneeyedcrock

Tue Aug 31, 2010 1:39 pm


Poster: paulsiew31

Tue Aug 31, 2010 1:09 pm


Poster: paulsiew31

Tue Aug 31, 2010 1:07 pm


Poster: oneeyedcrock

Tue Aug 31, 2010 12:35 pm


Poster: lcf13

Tue Aug 31, 2010 12:27 pm


Poster: garr75

Tue Aug 31, 2010 12:01 pm


Poster: lcf13

Tue Aug 31, 2010 2:03 am


Poster: lcf13

Tue Aug 31, 2010 2:00 am