The Register® — Biting the hand that feeds IT

Feeds

iPhone Mail bug adds phishing danger

Be careful around the net

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Flaws in the Mail and Safari applications bundled with the iPhone leave users of the device at greater risk of phishing attacks.

A URL-spoofing vulnerability means that a dodgy domain pointed to by a specially crafted URL can appear to be that of a trusted brand when viewed through the iPhone's mail or Safari browser applications.

Mail and Safari on version 1.1.4 and 2.0 of the iPhone firmware are affected by this vulnerability. Earlier versions may also be buggy. , Security researcher Aviv Raff, who found the flaw, is withholding technical details pending the release of patches from Apple.

iPhone users are advised to enter the addresses of sites they wish to visit manually instead of clicking on links contained in email. This is good advice generally but all the more important while there is no patch available.

The way the vulnerability affects Mail also leaves iPhone users more likely to receive spam, according to Raff, who reports that the consumer electronics giant has privately acknowledged the Mail vulnerability. Apple is still reportedly investigating the Safari-on-iPhone bug.

Raff is a prominent researcher in the arena of client side vulnerabilities, and has been credited in recent months with discovering or expanding research on flaws in Internet Explorer, Skype and Safari. ®

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Latest Comments
Anonymous Coward

Banks don't send email

You can safely ignore and delete any email that purports to come from a bank. Banks don't send email, they send old fashioned letters on old fashioned paper.

0
0

Iphone not the problem

I don't why you think this is an issue with the Iphone. The Iphone and all products that Apple make are beyond critism from any mere mortals.

Obviously this is a flaw with the rest of the universe and this need to be changed to ensure that it doesn't impact upon any his Jobiness creations.

PS. Obviously if a similar exploit if found any other operating system then its obvioulsy a major security issue with that system anybody using that system should be struck down by lightning.

0
0

Robot says...

Maybe hardware not the weak link. Maybe other thing. BEEP.

0
0

More from The Register

 breaking news
UK telcos chuck another £1m at online child abuse watchdog
Web enforcers IWF gain power to seek and destroy illegal content
 breaking news
Pttow! Ofcom kicks hams out of MoD bands
Geet off my land, you, you ... 'secondary user'
 breaking news
Now you can use your phone instead of your wallet at the ATM, too
Blimey, these little paper towels out of the vending machine are really expensive
 breaking news
UK.gov's £530m bumpkin broadband rollout: 'Train crash waiting to happen'
Whitehall whispers of damning watchdog report next month
Google launches broadband balloons, radio astronomy frets
A careless Loon could blind the square kilometre array
 breaking news
MySpace zaps millions of teens' tearful rants, causes wave of angst
'Your crappy redesign SUCKS, I wanna read my blogs' screech users
 breaking news
Microsoft Office 365 on iPhone NOW: No, we're not making this up
Word, Excel, Powerpoint for your pocket-stroker
 breaking news
EU signs off on eCall emergency-phone-in-every-car plan
GPS and a mobe in every car - do you suppose the NSA would fancy that?