Apple iPhone
A security expert has warned that malicious code could be disguised as phone links

iPhone dialler labelled security risk

Users urged to avoid automatic dialling via Safari

Written by Shaun Nichols in California

Users of Apple's iPhone are being advised to avoid automatically dialling numbers from web pages after a researcher outlined possible security flaws. 

The vulnerability lies within the iPhone's ability to automatically dial numbers listed on web pages via the Safari browser.

SPI Labs lead researcher Billy Hoffman warned in a company blog that malicious code could be disguised as phone links and used to run up service charges or render the iPhone useless. 

Other possible implications of the vulnerability include cross-site scripting attacks, tracking a user's phone activity or causing a denial-of-service attack.

Hoffman said that the issue has been reported to Apple, and advised users to avoid following phone links in Safari until the company can issue a fix.

Other experts downplayed the risk, however. Paul Moriarty, director of internet content security at Trend Micro, told vnunet.com that similar avenues for attack have been found in other smartphones, and there is normally little danger to users. 

"If you want to get a headline, maybe, but you are not going to make a whole lot of money," he said.

Moriarty explained that duping users into dialling premium numbers is not a solid business plan, given the policies of many service providers.

"If I call AT &T and dispute [the charges] the chances are they are going to erase it and hit the other company back for the money," he said.

"It strikes me as a much less convenient way to make money if I already have the skills to go out and conquer PCs."

Moriarty pointed out that there are only a million or so iPhones out there to exploit, but hundreds of millions of poorly maintained PCs with unpatched vulnerabilities ripe for attack.

Tags:

reader comments

related articles

Apple iPhone

Special Report: Apple iPhone

All the latest news on Apple's iPhone 18 Dec 2007

 

Zombie botnet targets iPhone buyers

'One of the most sophisticated' scams in recent times 16 Jul 2007

Hack brings Skype to iPhone

Complex workaround fulfils geek dream 12 Jul 2007

Apple iPhone passes security muster

Safe for now, but uncertain future 11 Jul 2007

Hackers step up website attacks

Security forecast for 2008 makes grim reading 20 Feb 2008

iPhone vulnerable to DoS attack

Apple's mobile browser flawed, claims security firm 16 Apr 2008

Apple patches critical Safari holes

Four flaws addressed in latest update 17 Apr 2008

related whitepapers

today's top stories

Panning for data gold - a guide to information management

Progressive IT chiefs are teaming up with business leaders to provide users with compelling new ways to sift through and make sense of corporate data 06 Jan 2009

Review 2008: Top 10 most-read stories of the year

We reveal the 10 articles from 2008 that you read more than any others on Computing.co.uk during the year 02 Jan 2009

Flash teddy

A reader who didn't sign his name sent us a very useful compendium of amusing USB drives, from which we take this... 06 Jan 2009

Using business process management to thrive through the downturn

Our panel of experts discuss how to bridge the IT-business gap 06 Jan 2009

Review 2008: Top 10 IT leader interviews

We look back on the best of Computing's exclusive interviews with the most influential leaders in UK IT 22 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Should the government cut costs by scrapping major IT projects?

Should the government cut costs by scrapping major IT projects?

Tell us what you think

Previous poll results

Latest audio and video articles

Podcast imageAudio

Computing podcast - the highlights of 2008

The Computing team pick their personal favourites of the year 18 Dec 2008

Xperia X1Video

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1 12 Dec 2008

Latest in-depth articles

Eugene KasperskyAnalysis

Q&A: Kaspersky Lab's Eugene Kaspersky

Kaspersky Lab founder Eugene Kaspersky tells vnunet.com why the software industry could be losing its brightest stars to the world of online crime 30 Dec 2008

Mark LewisAnalysis

Q&A: EMC's Mark Lewis

Mark Lewis, president of EMC's content management and archiving division, discusses the firm's content management strategy with vnunet.com 31 Dec 2008

Advertisement

Primary Navigation