A memory corruption issue exists in the decoding of SMS and MMS messages and receiving a maliciously crafted SMS message may lead to an unexpected service interruption that could decode iPhone OS 3.0 including, photos, audio and contact info.
The attack is very simple: Once you have clicked the URL by sending a text message inviting bogus clicking on links, the hackers will have full control of your iPhone. This attack on MMS could allow an attacker to trick the recipient into visiting a malicious Web site or ultimately do something else to harm the iPhone or steal data. The attacks work potentially on any type of iPphone that is MMS-enabled and operating on GSM networks. In particular it is an operator problem and that has already been shared with the GSM Alliance.
Apple has to fix to the bug because according to statements by Apple they had never been applied on an iPhone but, can also be applied on the new firmware of iPhone 3.0.1. It is possible they would have been better not to give so much importance to this problem. However, it seems that all the hackers are paying attention on this bug, which is really beginning to get dangerous.
Note: MMS support from AT&T coming in late summer.
Free iPhone Security Update
The free iPhone OS Software Update includes some great new features, as well as all the features from previous updates. iPhone OS 3.0 also lets you run the next generation of iPhone apps and more. If you have never updated before, now is the perfect time.
Here are a few items to help with checking and improving the security of your iPhone3GS.
- You need to see the Mac OS X Security web page for an overview of Mac OS X security features
- Ensure that you are running the latest version of system software as Apple releases security updates regularly and having the latest available system software version should improve the security of your iPhone apps.
- Mac OS X Security Guides describe steps that can be taken to further enhance the security of your iPhone
- Additionally, the Mac OS X built-in security features from third-party providers could help to increase the security of your system in particular situations
