New iOS "Masque Attack" Security Vulnerability Found
David Curry | | Nov 11, 2014 08:27 AM EST |
(Photo : Reuters) iPhones were a big hit on Black Friday.
In the past month there have been quite a few vulnerabilities brought up on OS X and iOS, and now there is the newest malware bugknown as Masque Attack.
Like Us on Facebook
Spotted by FireEye Mobile earlier today, Masque Attack works by sending a phishing SMS message to the user with a link included. If the user clicks the link, they will be prompted to download a certain app, but instead of downloading the app, the malware bug will recreate an official app and masquerade as it.
In a demo of the findings, FireEye Mobile showed how an SMS linking to a "Flappy Bird" download allows the Masque Attack to intercept the Gmail app. Hackers could use this to take all sorts of information from vulnerable apps on iOS.
However, even with the potential damage Masque Attack could achieve, there have not yet been any reports of this affecting people. Fortunately, many users would not click a third-party link on an SMS message, and then press download from a third-party website.
Masque Attack can target users on iOS 7.1 to iOS 8.1 - Apple currently has not commented on the new hack. Not being able to download third party apps from the web browser seems like the obvious solution, or making sure users know the phone number is not recognized.
Users should always download from the official apps store. If their iPhone is "jailbroken," they should look toward reputable stores, which are known for having clean downloads. Apple has previously warned users on the potential problems of downloading from the web browser.
Unless hackers can find a way to gain access to iPhone phone numbers, this looks to be a smaller scale issue compared to WireLucker. The previous iOS, OS X issue affected 350,000 users, mostly in China, before being patched by Apple.
©2015 Chinatopix All rights reserved. Do not reproduce without permission
- Home Depot Blames Windows For Security Breach
- Apple iMessage Users Can Now Deregister From Service
- Sapphire Supplier GT Advanced Calls Apple "a Bully"
- Apple Removes FitBit From Stores, For Upcoming Apple Watch
- iPhone 7 May Feature Glasses-Free 3D Display
- Apple Fixes WireLucker Malware, Windows May Have Been Infected
EDITOR'S PICKS
-
Did the Trump administration just announce plans for a trade war with ‘hostile’ China and Russia?
-
US Senate passes Taiwan travel bill slammed by China
-
As Yan Sihong’s family grieves, here are other Chinese students who went missing abroad. Some have never been found
-
Beijing blasts Western critics who ‘smear China’ with the term sharp power
-
China Envoy Seeks to Defuse Tensions With U.S. as a Trade War Brews
-
Singapore's Deputy PM Provides Bitcoin Vote of Confidence Amid China's Blanket Bans
-
China warns investors over risks in overseas virtual currency trading
-
Chinese government most trustworthy: survey
-
Kashima Antlers On Course For Back-To-Back Titles
MOST POPULAR
LATEST NEWS
Zhou Yongkang: China's Former Security Chief Sentenced to Life in Prison
China's former Chief of the Ministry of Public Security, Zhou Yongkang, has been given a life sentence after he was found guilty of abusing his office, bribery and deliberately ... Full Article
TRENDING STORY
-
China Pork Prices Expected to Stabilize As The Supplies Recover
-
Elephone P9000 Smartphone is now on Sale on Amazon India
-
There's a Big Chance Cliffhangers Won't Still Be Resolved When Grey's Anatomy Season 13 Returns
-
Supreme Court Ruled on Samsung vs Apple Dispute for Patent Infringement
-
Microsoft Surface Pro 5 Rumors and Release Date: What is the Latest?