Malicious website can lock up iPhone/iPod Touch and crash Safari

March 23, 2008

picture-12 A new exploit circulating around for the iPhone/iPod Touch requires no user interaction to execute.  Websites with specifically written code are able to lock up your iPhone or iPod Touch and can crash your PC or Mac running Safari.

Most versions of Safari are vulnerable to the exploit including the version that runs on the iPhone or iPod Touch.  The exploit basically overruns the memory allocated to Safari and will your iPhone or iPod Touch to lock up or Safari on your desktop computer to crash.

According to Cnet, remote code execution may be possible but has not been confirmed at this time.  This new exploit is different from an earlier one that requires some user interaction to execute.

iPhone World has published either a text version of the code for your review or the exploit that will run but be warned, it will lock up your iPhone or iPod Touch and crash Safari running on a PC or Mac.

The latest version of Safari for PCs and Macs does not appear to be vulnerable to this exploit.  Apple has not commented on the issue but there’s no doubt in my mind the company is working on a firmware update to plug this hole on the iPhone and iPod Touch.

It is highly recommended to upgrade to the latest version of Safari on your PC or Mac and temporarily disable Javascript on your iPhone or iPod Touch as a temporary measure until Apple releases an update.


Related posts:

  1. iOS 4.3 now available; Safari’s sweet [u]
  2. Updated: iJailbreak: easy 1.1.3 jailbreak for iPhone and iPod Touch on Mac
  3. Apple issues security update for iPhone and Touch
  4. How to jailbreak your iPhone or iPod Touch
  5. iPod Nano, Touch revisions coming with iTunes 8.0

One Response to “Malicious website can lock up iPhone/iPod Touch and crash Safari”

  1. Think Geek Australia » Blog Archive » Apple changes SDK terms to allow some interpreted code:

    [...] a “Zune 2.0″ with the (3G) iPhone 2.0 ?iPhone OS 4.0 developer agreement bans use of FlashMalicious website can lock up iPhone/iPod Touch and crash SafariApple changes SDK terms to allow some interpreted code Posted in iPhone | Previous post: [...]

Leave a Reply:


Recent stories

Featured resources

Featured stories

RSS Technology news

RSS Windows news

RSS Mac news

RSS Mobile technology news

RSS Green tech

RSS Buying guides

RSS Gaming news

RSS Photography news

Archives

Copyright © 2012 Blorge.com NS