RSS

Ziphone creator crashes iPhone with malicious video file

Ziphone creator crashes iPhone with malicious video file

Piergiorgio Zambrini, who is perhaps better known as Zibri, the developer of Ziphone has recently gone public through Forbes offering details of how a video file can crash the iPhone. According to Zambrini, the video would have to be specially created and if played would cause the iPhone to crash instantly. He states that the bug involves the audio portion of Apple’s video format, and that while it will crash the iPhone and cause it to reboot it will not cause any permanent damage.

Currently Zambrini has not made any mention of whether this could be used maliciously, but that aside, it would be say to believe that Apple would not want to deal with a bunch of crashing iPhones.

According to Cameron Hotchkies who is a reverse engineer and Apple expert at TippingPoint, the fact that the video is able to crash the device and not just the browser “means he’s got a kernel vulnerability in the iPhone.”

As of now, Zambrini states that he is “still exploring the bug’s potential for malicious applications like arbitrary code injection,” of course as of now he has not yet found that serious of a security flaw. We can only hope that it remains that way.

[Forbes]

, , , , ,

Comments are closed.