Watch out for the iPhone’s 911 bug

A security researcher has discovered a bug in the iOS WebView that will allow an attacker to force an iPhone to dial any number and lock the phone’s interface so that the outgoing call can’t be cancelled. 

The issue has been raised by Collin Mulliner, who encountered a similar bug in the Safari browser in 2008 which was then fixed in the iOS 3 update. Mulliner decided to look back into the bug, he said, after reading a news story about a teenager who was arrested for apparently inadvertently exploiting a similar bug to flood 911 call centers across the US with calls. 

Mulliner found that the bug is slightly different to the one he uncovered in 2008 but believes he’s discovered how it works. 

Apps should ask first

The bug is first initiated when an iPhone user clicks a malicious link posted within apps such as Twitter and LinkedIn, which use the iOS WebView component to open an in-app web page rather than an external browser like Safari or Chrome.

The link takes the user to a webpage which forces the iPhone to dial the number embedded there and the page repeatedly reloads, freezing the device and making it impossible to cancel the call. 

The reason the iPhone is forced to dial the number is because the links in these apps are opened by WebView which auto-dials embedded numbers, unlike Safari which solved the previous iteration of the bug by asking the user via a pop up if they want to dial a number first. 

Exploiting the bug to DoS 911 call centers is certainly terrible, but Mulliner warns its not the only possible use of it, suggesting that such links could also take users to webpages embedded with expensive 900 numbers which would allow attackers to make money from victims. 

He even theorizes that a stalker could send a link embedded with their own number to their victim in order to force a call which would then provide the stalker with the victim’s number. 

In a blog post, Mulliner states he’s reported the bug to Apple but has also contacted LinkedIn and Twitter with his findings as he believes that app developers at that very least can review their use of WebView until Apple is able to change its default behavior. We hope they issue a patch quickly, it doesn't sound like this cloud has any silver linings.

Mulliner has posted a video of the bug in action, which you can watch below:

TOPICS
Emma Boyle

Emma Boyle is TechRadar’s ex-Gaming Editor, and is now a content developer and freelance journalist. She has written for magazines and websites including T3, Stuff and The Independent. Emma currently works as a Content Developer in Edinburgh.

Latest in iPhone
iPhone 16 Pro Desert Titanium in hand
I think the rumored iPhone 17 Pro redesign looks great – but is it Apple enough?
Apple iPhone 16 Review
New iPhone 17 report lends weight to rumors of major display and camera upgrades, and a pricey Apple foldable
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
The home screen on an iPhone 16e smartphone
I think the iPhone 16e is too expensive – and as it turns out, so does nearly everybody else
Apple iPhone 16 on orange background with big savings text overlay
You can get a free iPhone 16 Pro Max without a trade at Verizon right now - with one minor catch
Latest in News
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog