Original URL: http://www.reghardware.co.uk/2008/02/07/iphone_vuln_ipod_touch/
Security researchers have discovered you can crash an iPhone through the medium of a cleverly crafted webpage.
The exploit, dubbed a "memory exhaustion remote denial of service vulnerability" by the SecurityFocus website, affects Apple's Mobile Safari web browser, a key component of both the iPhone and the iPod Touch.
Code up a webpage a certain way - all it takes is 19 lines of JavaScript - and if you can persuade an iPhone user to view it, the site will trigger the handset's version of Mac OS X to experience a kernel panic and reboot.
It's considered possible that the exploit might also allow miscreants to load and run code on the handset, but as yet this hasn't been confirmed.
The exploit was first uncovered last month under version 1.1.2 of the iPhone's firmware, but this week it emerged that the vulnerability is also present in firmware 1.1.3.
As yet there's no fix for the bug beyond disabling JavaScript, which sufficiently concerned iPhone and iPod Touch owners can do through the Safari section of the device's Settings application.
Wi-Fi spoofing sends Jesus phone disciples off the true path (16 April 2008)
http://www.theregister.co.uk/2008/04/16/skyhook_spoofing/
The trinity of RIA security explained (8 April 2008)
http://www.theregister.co.uk/2008/04/08/ria_security/
Apple to announce iPhone and iPod Touch price cuts? (10 February 2008)
http://www.reghardware.co.uk/2008/02/10/apple_to_announce_iphone_and_ipod_touch_price_cuts/
Orange France iPhone total hits 90,000 (7 February 2008)
http://www.reghardware.co.uk/2008/02/07/orange_iphone_tally/
Apple iPhone storms world smartphone biz (6 February 2008)
http://www.reghardware.co.uk/2008/02/06/canalys_q4_07_smartphone_biz/
16GB iPhone to launch today (5 February 2008)
http://www.reghardware.co.uk/2008/02/05/16gb_iphone_to_launch_in_uk_today/
Easy iPhone unlocking for $30? (4 February 2008)
http://www.reghardware.co.uk/2008/02/04/brando_sim_card_unlock/
Malware authors target Mac emerging markets (25 January 2008)
http://www.theregister.co.uk/2008/01/25/mac_malware_menace/
Latest iPhone firmware unlocked (22 January 2008)
http://www.reghardware.co.uk/2008/01/22/iphone_jailbreak/