iPhone Owners, Beware: Hacker Reveals SMS Spoofing via iOS Security Flaw

By Alexandra Burlacu | Aug 19, 2012 12:47 PM EDT

Share This Story

  • Print
  • Email

A well-known French hacker has revealed a major security flaw that has existed in Apple's iPhone since the very first device launched in 2007. Known publicly only as "pod2g," the French iOS security researcher published details about the vulnerability on Friday, Aug. 17. According to him, the security flaw affects all versions of iOS, including the latest beta release of iOS 6.

Follow us

The hacker has identified a text-based iOS vulnerability that allows hackers to spoof their identities. According to pod2g's report, the reply-to number displayed when an iPhone user receives an SMS can easily be manipulated to display a different number than the one actually sending the message. Through a relatively simple procedure, malicious attackers can exploit this glitch to send messages that appear to be from a legitimate source, such as a bank. Any replies to the SMS would be routed to a separate phone number, and the sender would have no clue. Moreover, pod2g said the iPhone is not the only handset with this security vulnerability.

"In the text payload, a section called UDH (User Data Header) is optional but defines a lot of advanced features not all mobiles are compatible with," explained the hacker. "One of these options enables the user to change the reply address of the text. If the destination mobile is compatible with it, and if the receiver tries to answer the text, he will not respond to the original number, but to the specified one."

In the blog post on Friday the researcher said this flaw is "severe," and urged users to be very careful with SMS messages asking for sensitive information. "Apple: please fix this before the final release," wrote pod2g, referring to the latest beta release of iOS 6. "On iPhone, when you see the message, it seems to come from the reply-to number, and you [lose] track of the origin."

"Now you are alerted," said the researcher. "Never trust any SMS you received on your iPhone at first sight." The blog post did not mention whether pod2g had notified Apple of the flaw. In response to the issue, Apple said it "takes security very seriously."

"When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks," Apple said in a statement to Engadget. "One of the limitations of SMS is that it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown website or address over SMS."

Apple is expected to unveil the final version of iOS 6, along with its next-generation iPhone, at an event on Sept. 12. The company, however, has not made any official announcements.

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Galaxy S4 Google EditionSamsung Galaxy S4 Google Edition: $649 Price Tag Explained
Nokia EOS Details Allegedly Leaked: Once Again Nokia Focuses On The Camera
Samsung Galaxy Note 3 May Sport Same Familiar Plastic Design, Not Metal
Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Tablet / Laptop / PC
Nexus 7Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Dell XPS 10 Drops Price To $300, Marking A New Low For Windows RT
HP Slatebook x2 Convertible Laptop Rocks Nvidia Tegra 4, Android 4.2 Jelly Bean
Gadgets
Google GlassGoogle Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
OS / Software
Samsung Galaxy S4 Gets TCO CertificationSamsung Galaxy S4 Gets TCO Certification
Android 4.3 Jelly Bean Coming On June 10: Absent From Google I/O 2013 Intentionally
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
Google Wallet Update: Send Money To Friends With Gmail, Make One-Click Purchases On The Go
Internet / Social Media
The Yahoo logYahoo Is Eyeing Tumblr
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Gtalk Chat Integration Coming To Outlook.com
What's App
Intellicam Windows Phone 8Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around
Google I/O 2013: Chrome Web Browser Now Has 750 Million Active Users

DON'T MISS

Galaxy S4 White Frost
Verizon Samsung Galaxy S4 To Come On May 23
According to an update on Verizon's news page, the Galaxy S4 will now be available in Verizon
Galaxy S4 Google Edition
Samsung Galaxy S4 Google Edition Launched: Rumors Say It's Nexus 5
The new edition of the Galaxy S4 is being seen as an alternative to the Nexus smartphones as the
RIM BlackBerry 10
BlackBerry Live: 120,000 Apps in BlackBerry World, Gaining on Windows Phone
The numbers are in, and it appears BlackBerry World might walk over Windows Phone sooner or later.
Windows Blue
Windows 'Blue' Will Come As Free Update For Windows 8, Windows RT Users
Despite previous rumors, Windows 8.1 dubbed Windows 'Blue' will be available as a free update to
LG Google TV
Android 4.2.2 Jelly Bean, Chrome Update For Google TV: End Of Flash?
The Google TV has now be 'refactored' so the OEMs of the device can update their settop boxes to
Samsung Galaxy S4 'Blue Arctic'
Samsung Galaxy S4 Blue Arctic Gets Official On Docomo Network
Samsung Galaxy S4 Blue Arctic is real but it is not yet clear whether the handset is exclusively

Galaxy S4 White Frost
Samsung To Look Into 16GB Galaxy S4 Storage Woes, 'Software Optimization' Might Free More Space
Samsung has finally responded to storage woes concerning the 16GB Samsung Galaxy S4 and said it may
Samsung Galaxy S4 Mini 'Leaked' Image
Samsung Galaxy S4 Mini Spotted In Leaked Images Once Again
In the latest series of leaked pictures, the Galaxy S4 mini is shown from every possible angle and
Google Maps
Google I/O 2013: Google Maps Gets New UI And Google+ Hangouts Shows Massive Improvements
Fans of Google products will love the new look of Google Maps and Google+ Hangouts.
MSI GX70
AMD Unleashes Radeon 8900M Mobile GPU: Get It In MSI GX70 Gaming Laptop
Do you enjoy gaming on a laptop? The AMD Radeon 8900M might excite you along with the MSI GX70.
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics