Mobile // Mobile Devices
06:31 PM
Connect Directly

Apple iPhone Vulnerabilities Disclosed

The first is a URL display flaw in the iPhone's Mail that could allow an attacker to send a message containing a malicious URL that looks legitimate, says one security researcher.

After two and a half months of inaction from Apple, security researcher Aviv Raff on Thursday decided to release information about two iPhone vulnerabilities that he found and brought to the company's attention in July.

The first is a URL display flaw in the iPhone's Mail that could allow an attacker to send a message containing a malicious URL that looks legitimate.

"In most mail clients (e.g., on your PC / Mac), you can just hover the link and get a tooltip which will tell you the actual URL that you are about to click," explains Raff in a blog post. "In iPhone it's a bit different. You need to click the link for a few seconds in order to get the tooltip. Now, because the iPhone screen is small, long URLs are automatically cut off in the middle."

It's possible for an attacker to construct a long URL that displays a trusted domain but actually resolves to another domain entirely, he explains. The victim would only see the portion of the domain designed to look familiar and would be more likely to click on the malicious link.

Opening the URL in the iPhone's Safari browser would not help because it, too, only displays a portion of the long URL.

The iPhone Mail application also is vulnerable because of the way it handles images. Specifically, it automatically downloads images in HTML-formatted messages. Most mail clients provide a way to make the downloading of images require user approval. This protects against spammers, who can tell if an e-mail account is active if a spam recipient opens a message and downloads images.

"This one is not just a trivial bug," said Raff. "It's actually a pretty dumb design flaw, which was already fixed by all other mail clients ages ago."

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Building A Mobile Business Mindset
Building A Mobile Business Mindset
Among 688 respondents, 46% have deployed mobile apps, with an additional 24% planning to in the next year. Soon all apps will look like mobile apps – and it's past time for those with no plans to get cracking.
Register for InformationWeek Newsletters
White Papers
Current Issue
Top IT Trends to Watch in Financial Services
IT pros at banks, investment houses, insurance companies, and other financial services organizations are focused on a range of issues, from peer-to-peer lending to cybersecurity to performance, agility, and compliance. It all matters.
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
Join us for a roundup of the top stories on for the week of October 9, 2016. We'll be talking with the editors and correspondents who brought you the top stories of the week to get the "story behind the story."
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll