One of the iPhone’s most nifty features — dialing any phone number by simply tapping on a Web page — can be its most sinister.
Security researchers at SPI Labs says this feature can be exploited by hackers to pull off nefarious stunts like redirecting phone calls placed by the user to different phone numbers of the attacker’s choosing; tracking phone calls placed by the user; tricking the phone into placing a call without the user accepting the confirmation dialog; or placing the phone into an infinite loop of attempting calls, through which the only escape is to turn off the phone.
SPI Labs lead researcher Billy Hoffman, a Web application security specialist, warned that these types of attacks can be launched from a malicious website, from a legitimate website that has CSS (cross-site scripting) vulnerabilities, or as part of a payload of a web application worm.
The day my
iphone touch screen died |