Android Stagefright like attack for iPhone, All it takes is a specially crafted message to hack your iPhone
If you remember the Stagefright vulnerability in Android discovered in Julyย last year, you will know that a potential hacker can gain full access to your smartphone just by sending a specially crafted multi-media message. The Apple’s iOS ย operating system also has a similar vulnerability which can be used by potential hackers to remotely take over your iPhone
This highly critical bug in iOS was discovered byย Cisco Talos senior researcher Tyler Bohan, who described the flaw as “an extremely critical bug, comparable to the Android Stagefright as far as exposure goes.”
The critical bug has already assigned a CVE-2016-4631 and resides in ImageIO โ API used to handle image data โ and works across all widely-used Apple operating systems, including Mac OS X, tvOS, and watchOS. According to Bohan, the that the potential hacker needs to do is create an exploit for the bug and send it via a multimedia message (MMS) or iMessage inside a TIFF (Tagged Image File Format) format file. Once the hacker sends the message to an iPhone owner, the exploit is executed. The user would have no chance of detecting the attack, which would begin to write code beyond the normal permitted boundaries of an iPhoneโs texting tool.
.The attack could also be delivered through Safari web browser. For this, the attacker needs to trick the victim into visiting a website that contains the malicious payload.
The attack which is similar to Android’s Stagefright vulnerabilityย can also be exploited by making the iPhone owner visit a malicious website containing the malicious payloadย through iOS default Safari browser. As in Stagefright, the iOS bug also requires no explicit user interaction would be required to launch the attack since many applications (like iMessage) automatically attempt to render images when they are received in their default configurations.
As said above, the bug can be exploited unknown to the hapless iPhone owner and can give the hacker access to the victim’s authentication credentials stored in memory such as Wi-Fi passwords, website credentials, and email logins. However, for taking full access to the victim’s iPhone, theย hacker would need a further iOS jailbreak or root exploit. Thatโs because iOS enjoys sandbox protection, which prevents hackers exploiting one part of the operating system to own the whole thing.
The bugs uncovered by Bohan work across all widely-used Apple operating systems, however, including Mac OS X, tvOS and watchOS. Bohan noted that as Mac OS X doesnโt have sandboxing like iOS, it offers the potential hacker a full opportunity for exploiting the above bug and remotely taking over the Mac with the victim’s password. This makes Apple’s MacBooks highly vulnerable to a remote takeover through simple specially crafted email.ย โExploitation wise, Talos estimates there is about a two-week effort to get
โExploitation wise, Talos estimates there is about a two-week effort to get from the information we disclosed publicly to a fully working exploit with a decent amount of reliability,โ Bohan added.ย also found memory corruption issues in iOSโ CoreGraphics, which helps render 2D graphics across those OSes.
Bohan also found memory corruption issues in iOSโ CoreGraphics, which helps render 2D graphics across those OSes. Anotherย serious flaws patched by Apple this week residedย in FaceTime, permitting anyone on the same network as a user to spy on their conversations. As per Appleโs description, โan attacker in a privileged network position may be able to cause a relayed call to continue transmitting audio while appearing as if the call terminated.โ Martin Vigo, a security engineer at Salesforce, uncovered the bug.
Details on all 43 flaws addressed in 9.3.3 can be found inย Appleโs advisory. Apple has taken congnizance of the severity of the bug and put out separate advisories for iTunesย on Windows,Safari, tvOS, watchOS and OS X El Capitan.