Serious security flaw found in iOS text messages

iMessage
A new security flaw has been in found in iOS SMS text messages

While there are a great deal of hackers out there who exist solely to cause trouble for hardware and software makers, as well as their customers, there are a few diamonds in the rough.

Case in point, the hacker "pod2g," who spends his time discovering security exploits not to make use of them, but to make consumers and companies alike aware of problems.

His latest discovery is quite astounding, especially when you consider Apple is about to make a big push with their latest operating system, iOS 6.

The flaw in question affects every single version of iOS, including the most recent beta version of iOS 6, and allows hackers to send spoofed text messages to other phones without any indication they are fraudulent.

Is that text really from your bank?

As "pod2g" points out, when text messages are sent out, they are converted in the phone's Protocol Description Unit (PDU).

By accessing this PDU data, hackers are potentially able to utilize the User Data Header to mask the reply number in the text.

Typically, you would be able to see both the original and altered numbers. However, that's just not the case on the iPhone.

Thus the origin of the SMS remains hidden, and hackers can dupe recipients into believing they are getting a text from a trusted source such as their bank.

Fortunately, this only applies to SMS messages, and not messages sent across Apple's iMessage service.

Apple has yet to address the issue, however "pod2g" plainly states if he was able to discover the flaw, so were some other less forthcoming individuals.

Via ZDNet and pod2g

TOPICS
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Close up of Leica M11-P viewfinder
I wince at the prospect of the rumored Leica M11-V – here's why
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time