Saturday, August 23, 2014

On the iPhone detected zero-day vulnerability associated with calls to premium rate numbers

Experts found on the iPhone a serious vulnerability that can hit on the wallet of their respective owners. By posting malicious links to sites on the Internet, attackers can initiate calls on the dates of their rooms. If the owner of an iPhone will go on such a link, the smartphone will carry out a paid call.
call-1

According to Hi-News, vulnerability found employees Airtame. In most cases, Safari offers the user a choice: to call or not to call the number indicated, but some third-party applications, such as Facebook or Google+ messenger bypass this step and immediately begin dialing.
Given that a malicious link can be sent in plain messages in social networks and even iMessage - is a good chance that the user really will go through it, without knowing it, become poor for a certain amount of money.
"We discovered a vulnerability that attackers can use to bypass the protection iOS on making calls without the knowledge of the user. Creating a web page with a special code JavaScript, an attacker can initiate a call to the iPhone paid number "- said the expert Airtame.
In addition to the Facebook Messenger and Google+, this vulnerability affects also Gmail and FaceTime. Experts Airtame led code link , when clicked, iPhone immediately goes to a call to the specified number in it.
FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF