Printed from http://www.electronista.com

iOS vulnerability could allow keyboard, button logging by attackers

updated 03:43 pm EST, Tue February 25, 2014

Even patched versions of iOS 6, 7 are exposed, firm says

A vulnerability in iOS could allow remote hackers to log every keyboard and button press a person makes, says security firm FireEye. The exploit is only theoretical -- and would require a compromised app to somehow make it through the App Store review process -- but is said to have been tested and could potentially expose both software and hardware interactions. This includes Touch ID unlocks, although not the actual fingerprint data involved.

The hole is present in even the latest versions of iOS 6 and 7. A now-deleted FireEye blog post claimed that the company actually passed a proof-of-concept app through the App Store, but that it's "collaborating with Apple" on the issue.

iOS appears to be exposed to the problem through the resources it offers to apps running in the background. If so, the main way of avoiding attacks until a patch is released is simply to avoid questionable apps, or if all else fails kill their processes using the iOS task switcher.




By Electronista Staff
Post tools:

TAGS :

toggle

Comments

  1. Marook

    Forum Regular

    Joined: 05-05-99

    1: 'remote hackers'?
    If at all usable, YOU need to put the App on your iDevice! There is NO remote 'hacking' in this regard!

    2: What userdata can they get? You would need to know the Locale the iOS device is running in, and then parse the _potential_ keypad keys pressed, if it's a keypad/board.. Or is there alphanumeric data in the events? Don't think so...!

Login Here

Not a member of the MacNN forums? Register now for free.

toggle

Network Headlines

toggle

Most Popular

Sponsor

Recent Reviews

Tablo DVR

With over-the-top content options growing past Hulu and Netflix, consumers may be finding it harder to justify paying a monthly fee fo ...

Sound Blaster Roar Bluetooth speaker

There could very well be a new king of the hill for Bluetooth speakers, with Sound Blaster's recent entry into the marketplace. Bringi ...

Kenu Airframe Plus

Simple, stylish and effective, the Kenu Airframe + portable car mount is the latest addition to Kenu's lineup. Released earlier this y ...

Sponsor

toggle

Most Commented

 
toggle

Popular News