iOS WebView Problem Allows Attackers to Initiate Phone Calls [telecom]

iOS WebView Problem Allows Attackers to Initiate Phone Calls

by Michael Mimoso

iOS developers who have embedded Apple's WebView into mobile apps need to be aware of an exploitable issue that could allow phone calls to a number of the attacker's choosing.

Researcher Collin Mulliner said the vulnerability is trivial to exploit, requiring at a minimum one line of HTML code. The risks to the user include ramped up charges to premium numbers, or worse, denial-of-service attacks similar to one last week that landed an Arizona man in jail for an exploit he shared on YouTube that allowed users to flood 911 call centers with calls just with one click.

See more at: iOS WebView Problem Allows Attackers to Initiate Phone Calls

formatting link

Reply to
Monty Solomon
Loading thread data ...

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.