PDA

View Full Version : App security flaw makes your iPhone call without asking



wraggster
August 28th, 2014, 15:24
http://o.aolcdn.com/hss/storage/midas/1ad81967f611e3346c01bb0b4111039c/200630545/facebook-messenger-phone-number.jpg (http://www.engadget.com/2014/08/24/automatic-phone-call-exploit/)
If you're an iPhone user, you may want to be cautious about opening messages that contain phone numbers in the near future; they may cost you a lot of money. Developer Andrei Neculaesei notes (http://algorithm.dk/posts/rtfm-0day-in-ios-apps-g-gmail-fb-messenger-etc) that maliciously coded links in some apps will abuse the "tel" web handler (which covers dialing) to automatically make a phone call the moment you view a message. Potentially, an evildoer could force you to call an expensive toll number before you've had a chance to hang up. The exploit isn't limited to any one app or developer, either. Facebook Messenger, Gmail and Google+ all fall prey to the attack, and it's likely that other, less recognizable apps exhibit similar behavior. Apple's Safari browser will ask you before starting a call, but FaceTime's behavior lets you pull a similar (though not directly related) stunt.

http://www.engadget.com/2014/08/24/automatic-phone-call-exploit/