Technology content trusted by users in Australia and around the world.
4,966 Articles | 29,991 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

AU EditionYou are located: Home > All News > Hacking & Security News > iOS 5 contains Safari bug, opens users to malicious sites

iOS 5 contains Safari bug, opens users to malicious sites

By: (more) | Hacking & Security News | Posted: Mar 23, 2012 4:31 pm

This is a cautionary story for all of those iOS 5 users out there, including the new iPad 3 users. Germany security firm MajorSecurity discovered a bug earlier this month that can be used to trick you into visiting potentially malicious Web sites. The bug was first discovered in iOS 5 and was replicated in iOS 5.1. Apple was informed of the bug by MajorSecurity on March 3, but has not yet issued a patch.

 

[img]2[/img]

 

"The weakness is caused due to an error within the handling of URLs when using javascript's window.open() method," explained David Vieira-Kurz of MajorSecurity. "This can be exploited to potentially trick users into supplying sensitive information to a malicious Web site, because information displayed in the address bar can be constructed in a certain way, which may lead users to believe that they're visiting another web site than the displayed web site."

 

Apple has acknowledged the bug, so they should be able to produce a patch, and I would encourage you to upgrade when it becomes available. Until then, watch the sites you go to, as it may not be where the URL bar is telling you you are at. If you would like to see for yourself, go here on your mobile device, select Demo in the upper left corner. This will open a new page that says Apple and looks like Apple but is still on MajorSecurity's server.


SOURCE #1

Related Tags



Further Reading: Read and find more Hacking & Security news at our Hacking & Security news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: Western Digital Scorpio Blue (WD5000LPVT) 500GB HDD Review
  • Upcoming Content: Scythe Mugen 4 Tower CPU Cooler Review
  • Upcoming Content: NZXT Grid 10 Port Fan Hub Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Hacking & Security News Posts

View More Hacking & Security News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Hacking & Security Press Releases

View More Hacking & Security Press Releases