Apple’s pretty proud of its App Store approval system. Too bad security hacker Andy Miller found a code-signing flaw that allows good apps to go bad. Here’s how an app downloaded from the App Store could become a malware threat.
What Miller has discovered is that hackers can create an app that passes Apple’s strict app vetting process and once that app is in the App Store can exploit a flaw in the code signing of Apple’s devices. The flaw is found in iOS 4.3 and later. At issue is that javascript is now allowed to run at a much deeper level than before to speed up mobile Safari. Apple actually created an exception for the browser to run unapproved code in an iOS devices memory.
Because of this, an Apple-approved app can phone home once launched and download malicious code that can run amok on the iOS device. A hacker could see a user’s contacts and photos, play sounds on the phone and activate vibrate mode. While remotely making an iPhone vibrate sounds innocuous, control of these aspects of an iOS device could potentially lead to control of other features. Check out the video above of the flaw in action.
Apple has already pulled Miller’s proof-of-concept InstaStock app from the App Store. Miller plans to demonstrate the flaw next week at the SysCan conference in Taiwan. [Forbes via Cult of Mac]



















Peter
Tuesday, November 8, 2011 at 10:49 AMSomeone just hopped the walled garden!
Richard
Tuesday, November 8, 2011 at 10:52 AMThey will probably tread on a rake soon.
Awnshegh
Tuesday, November 8, 2011 at 12:02 PMAgreed Apple are more likely to stamp on the fault finder for some legal breach of the EULA than admit the fault itself.
Entilzha
Tuesday, November 8, 2011 at 1:12 PMYep booted him from the App store.
http://www.cultofmac.com/128577/apple-kicks-security-researcher-out-of-app-store-and-developer-program-after-ios-vulnerability-demonstration/
Perri
Tuesday, November 8, 2011 at 12:43 PMThe best part about this video was his motivational poster on his wall.
Entilzha
Tuesday, November 8, 2011 at 12:59 PMHEHE I love a Rick Rolling iPhone App.
Lolz
Tuesday, November 8, 2011 at 11:58 PMOh god what a loser, “Hack like a champion today”? This guy probably still lives with his parents. Bet he jizzes in his pants every time he gets a new release of spergdroid for his phone.