Facebook to fix flaw that can force iPhones to make calls
Posted on 26 August 2014.
Facebook will soon be pushing out an update to its iOS Messenger app meant to patch a vulnerability that could allow attackers to place pricy calls from users' phones by simply making them click on a web link.

The flaw has been recently discovered by developer Andrei Neculaesei from Copenhagen, and can be triggered by using the tel URL scheme.

"The tel URL scheme is used to launch the Phone app on iOS devices and initiate dialing of the specified phone number," it is explained in an Apple document.

"When a user taps a telephone link in a webpage, iOS displays an alert asking if the user really wants to dial the phone number and initiates dialing if the user accepts. When a user opens a URL with the tel scheme in a native app, iOS does not display an alert and initiates dialing without further prompting the user."

A native app can be configured to display its own alert, Neculaesei says, but unfortunately many developers have not. He checked some popular iOS apps out there - Facebook Messenger, Gmail, Google+ - and all three didn't make the necessary change and were vulnerable to the proof-of-concept attack devised by Neculaesei.

"A lot of people make fake assumptions such as links are only clicked by users," he noted, but he used javascript to make the link click itself, and a call is established right away without the user being asked about it.

He also tested Apple's Facetime app, that apparently has a URL scheme just like tel, and can be used by attackers to see the face, and possibly discover the location and the identity of the target.

Neculaesei says that there are likely many iOS apps out there that allow this type of attack, and that its developers should configure the alerts in question.

The issue was also flagged earlier this month by information security consultant Guillaume Ross in his talk at BSidesLV 2014.









Spotlight

How to talk infosec with kids

Posted on 17 September 2014.  |  It's never too early to talk infosec with kids: you simply need the right story. In fact, as cyber professionals itís our duty to teach ALL the kids in our life about technology. If we are to make an impact, we must remember that children needed to be taught about technology on their terms.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Sep 19th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //