Safari DoS vulnerability could crash your Apple iPhone

happygeek 0 Tallied Votes 702 Views Share

According to IT Pro the Apple iPhone is vulnerable to Denial of Service attacks. These can occur when an iPhone user opens a JavaScript containing HTML page which triggers the vulnerability. An application Denial of Service attack can then crash the Safari browser on the phone, and quite possibly the iPhone itself.

The vulnerability actually lies with the Safari web browser that is used within the latest version 1.1.4 of the Apple iPhone software, and has been uncovered by integrated application delivery solutions outfit Radware which funnily enough is also offering a solution in the form of its own Security Update Service.

Radware warn that the vulnerability, which obviously has to have a user visiting an 'infected' web page using the iPhone in order to trigger the DoS attack, could be driven by a social engineering exploit using either email or SMS text messaging. The browser is vulnerable due to a design flaw that may be triggered by a series of memory allocation operations on the dynamic memory pool, according to Radware. This in turn can trigger a bug in the garbage collector, and the security hole is currently unpatched.

"While vendors are struggling to push new products and applications, it is evident that security still remains a secondary concern" says the Security Operation Centre Manager at Radware, Itzik Kotler who continues "hackers continue to misappropriate other people's software and their job is made easier by design flaws embedded into software products".

Dani AI

Generated

Brief, practical update and mitigation notes that fill gaps left by the original posts.

This issue was a WebKit/Safari client-side bug from early 2008: specially crafted HTML/JavaScript could exhaust memory or corrupt parsing and crash Mobile Safari (in some cases causing broader device instability). Researchers published proof-of-concept details and CVE tracking for the JavaScript/array and related WebKit flaws. (coresecurity.com)

Apple addressed a set of these Safari/WebKit vulnerabilities in the iPhone OS updates released later in 2008 — notably iPhone OS 2.2 (distributed starting November 21, 2008) — so the practical fix for impacted phones at the time was to update to the patched OS via iTunes. The vendor bulletin lists the affected components and CVE IDs for reference. (support.apple.com)

If an immediate OS update isn’t possible, the best short-term mitigations are simple and still effective for the class of bug described: disable JavaScript in Mobile Safari and avoid opening links from unknown SMS/email sources. On older iPhone firmware this is done in Settings → Safari → Advanced → turn JavaScript off. Treat jailbroken devices as higher risk because many app/OS protections are bypassed. (scribd.com)

Notes tied back to the thread: ’s original alert pointed to the problem; this post adds the CVE/patch timeline and concrete user steps. ’s Pocket PC theme comment is an interesting UI workaround but does not affect browser or OS security — theming a different device won’t mitigate a Mobile Safari exploit. For anyone finding this thread years later: verify the device can receive supported iOS updates; if not, avoid using it for sensitive browsing or move to a device that still receives security updates. (support.apple.com)

kumaran83 0 Newbie Poster

I don't know why people are suffering with unlocking and all the blah blah with apple iphone.

I have a Pocket PC, I used a iphone theme () and everything worked like a magic to me. Now I'm having the iphone experience in my Pocket PC.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.