iPhone URL Display Feature Poses Security Threat

· by · News

The system the iPhone, iPad and iPod touch use to display Web sites within apps offers hackers an easy way to trick users into visiting malicious Web pages posing as legit sites, according to security research specialist Nitesh Dhanjani. The spoof involves Apple’s UIWebView API and iOS’s ability to hide the URL field once a page loads.

The potential security flaw works by hiding the URL field for a Web page so users don’t notice that they aren’t on the Web site they intended. In situations where users should see the URL field, hackers can simply create their own showing the address their victim expects to see.

Mr. Dhanjani has detailed the flaw on his own blog as well as the SANS SSI Web site.

Mr. Dhanjani has passed the information on to Apple. “I did contact Apple about this issue and they let me know they are aware of the implications but do not know when and how they will address the issue,” he said.

Jeff Gamet

Jeff Gamet

Jeff is the Mac Observer's Managing Editor, and co-host of the Apple Context Machine podcast. He is the author of "The Designer's Guide to Mac OS X" from Peachpit Press, and writes for several design-related publications. Jeff has presented at events such as Macworld Expo, the RSA Conference, and the Mac Computer Expo. In all his spare time, he also co-hosts the We Have Communicators podcast, and makes guest appearances on several other podcasts, too. Jeff dreams in HD.

Sign Up for the Newsletter

Enter a valid email address

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

Adding to list…

1 Comments

Lee Dronick

Well Apple better provide a fix by 4:03 PM or I am going to post how-to info all over the internet.

Add your comment

Remember my personal information

Notify me of follow-up comments?