New Vulnerability Allows DoS Attacks on iOS Devices
Security researchers have identified a vulnerability in Apple's in iOS 8 that lets attackers crash iPhones and iPads within range of a wireless hotspot. The bug was presented earlier this week during the RSA Conference by Adi Sharabani, CEO and my fellow co-founder at Skycure.
By generating a specially crafted SSL encryption certificate, attackers can regenerate a bug and cause apps that perform SSL communication to crash at will. As SSL is a security best practice and is utilized in almost all apps in the Apple app store, the attack surface is very wide.
Skycure researchers found the iOS bug while experimenting with various ways to connect devices to a network. When they brought in a new router and changed the wireless configuration, programs on devices running Apple software began crashing.
Hackers controlling the network that the device is on can also control the certificates that are normally being used to securely transfer data, and use them for a so-called "denial of service" attack.
In the worst case, the devices can be forced into reboot cycles that can only be broken if the customer moves out of range of the malicious network, Sharabani said. Users should make sure to upgrade their operating system soon, and be wary of using public local wireless networks, Skycure said.
The security firm has reported the issue to Apple.