(Press-News.org) Researchers from the Georgia Tech Information Security Center (GTISC) have discovered two security weaknesses that permit installation of malware onto Apple mobile devices using seemingly innocuous applications and peripherals, uncovering significant security threats to the iOS platform.
"Apple utilizes a mandatory app review process to ensure that only approved apps can run on iOS devices, which allows users to feel safe when using any iOS app," said GTISC Associate Director Paul Royal, also a research scientist in the College of Computing. "However, we have discovered two weaknesses that allow circumvention of Apple's security measures."
Using different approaches, research scientists Tielei Wang and Billy Lau learned that malware can be installed onto iOS devices via Trojan Horse-style applications and peripherals. Wang's approach hides malicious code that would otherwise get rejected during the Apple review process. Once the malicious app passes review and is installed on a user's device, it can be instructed to carry out malicious tasks.
Wang's team developed a proof-of-concept attack, called Jekyll, which rearranges its own code to create new functionality that is not exhibited during Apple's approval process. This allows the malicious aspects of the app to remain undetected when reviewed and therefore obtain Apple's approval.
"We were able to successfully publish a malicious app and use it to remotely launch attacks on a controlled group of devices," said Wang. "Our research shows that despite running inside the iOS sandbox, a Jekyll-based app can successfully perform many malicious tasks, such as posting tweets, taking photos, sending email and SMS, and even attacking other apps -- all without the user's knowledge."
Taking a different approach, Lau decided to investigate the extent to which security threats were considered when performing everyday activities such as charging a device. Lau and his team created a proof-of-concept malicious charger using a small, inexpensive single-board computer. Called Mactans, it can easily be constructed to resemble a normal iPhone or iPad charger. However, once plugged into an iOS device, Mactans stealthily installs a malicious app.
"Despite the plethora of defense mechanisms in iOS, Mactans was able to install arbitrary apps within one minute of being plugged into current-generation Apple devices running the latest operating system software," said Lau. "All users are affected, as our approach requires neither a jailbroken device nor user interaction."
Both Wang and Lau's teams notified Apple upon the discovery of these security weaknesses. Following GTISC's disclosure of Mactans, Apple implemented a feature in iOS 7 that notifies users when they plug their mobile device into any peripheral that attempts to establish a data connection. Apple has indicated that it is continuing to work on ways to address the weaknesses revealed through Jekyll and, as of yet, has not publicly released a solution.
"These results are concerning and challenge previous assumptions of iOS device security," said Royal. "However, we're pleased that Apple has responded to some of these weaknesses and hope that they will address our other concerns in future updates."
###
Lau and Wang's findings are summarized in two papers: "Mactans: Injecting Malware into iOS Devices via Malicious Chargers," to be presented at the Black Hat USA 2013 conference July 27-Aug. 1 in Las Vegas; and "Jekyll on iOS: When Benign Apps Become Evil," to be presented at the 2013 USENIX Security Symposium August 14-16 in Washington, D.C.
Georgia Tech uncovers iOS security weaknesses
Attackers can compromise your iPhone through chargers and apps
2013-07-31
ELSE PRESS RELEASES FROM THIS DATE:
Sediment trapped behind dams makes them 'hot spots' for greenhouse gas emissions
2013-07-31
With the "green" reputation of large hydroelectric dams already in question, scientists are reporting that millions of smaller dams on rivers around the world make an important contribution to the greenhouse gases linked to global climate change. Their study, showing that more methane than previously believed bubbles out of the water behind small dams, appears in ACS' journal Environmental Science & Technology.
Andreas Maeck and colleagues point out that the large reservoirs of water behind the world's 50,000 large dams are a known source of methane. Like carbon dioxide, ...
Study offers promising new direction for organ regeneration and tissue repair
2013-07-31
BOSTON – Because most human tissues do not regenerate spontaneously, advances in tissue repair and organ regeneration could benefit many patients with a wide variety of medical conditions.
Now a research team led by investigators at Beth Israel Deaconess Medical Center (BIDMC) and Dana-Farber/Boston Children's Cancer and Blood Disorders Center has identified an entirely new approach to enhance normal tissue growth, a finding that could have widespread therapeutic applications.
Their findings were published on-line this week in the Proceedings of the National Academy ...
Chemical company giants stall with global economy
2013-07-31
The world's 50 largest chemical companies — with combined 2012 sales of almost $1 trillion and products that touch the lives of people everywhere — are the topic of the cover story in the current edition of Chemical & Engineering News. C&EN is the weekly newsmagazine of the American Chemical Society, the world's largest scientific society.
In C&EN's annual snapshot of the sales, profits, R&D spending and other indicators, Senior Correspondent Alexander Tullo points out that the Asian and Middle Eastern juggernauts that shot up the top 50 rankings during the past decade ...
New poll shows minority populations support clinical trials to improve health of others
2013-07-31
ALEXANDRIA, Va.—July 31, 2013—Altruism is a strong motivating factor for clinical trial participation in the general population and even more so among several minority groups. A significant percentage of African-Americans (61%), Hispanics (57%) and Asians (50%) say it's very important to participate as a volunteer in a clinical trial to improve the health of others, compared to 47% of non-Hispanic whites, according to a new national public opinion poll commissioned by Research!America.
These findings are tempered by the reality that participation remains disturbingly ...
3-D molecular syringes
2013-07-31
This news release is available in German. Abdominal pain, fever, diarrhoea -- these symptoms could point to an infection with the bacterium Yersinia. The bacterium's pathogenic potential is based on a syringe-like injection apparatus called injectisome. For the first time, an international team of researchers including scientists at the Helmholtz Centre for Infection Research (HZI) in Braunschweig, Germany, has unraveled this molecular syringe's spatial conformation. The researchers were able to demonstrate that the length of Yersinia's injectisome's basal body, which ...
VCU physicists discover theoretical possibility of large, hollow magnetic cage molecules
2013-07-31
Virginia Commonwealth University researchers have discovered, in theory, the possibility of creating large, hollow magnetic cage molecules that could one day be used in medicine as a drug delivery system to non-invasively treat tumors, and in other emerging technologies.
Approximately 25 years ago, scientists first made the discovery of C60 fullerene – better known as the Buckminster Fullerene – a molecule composed of 60 carbon molecules that formed a hollow cage. Due to its unique hollow cage structure the molecule offers serious technological potential because it could ...
Tiny, brightly shining silicon crystals could be safe for deep-tissue imaging
2013-07-31
BUFFALO, N.Y. — Tiny silicon crystals caused no health problems in monkeys three months after large doses were injected, marking a step forward in the quest to bring such materials into clinics as biomedical imaging agents, according to a new study.
The findings, published online July 10 in the journal ACS Nano, suggest that the silicon nanocrystals, known as quantum dots, may be a safe tool for diagnostic imaging in humans. The nanocrystals absorb and emit light in the near-infrared part of the spectrum, a quality that makes them ideal for seeing deeper into tissue ...
Robots strike fear in the hearts of fish
2013-07-31
Brooklyn, N.Y.—The latest in a series of experiments testing the ability of robots to influence live animals shows that bio-inspired robots can not only elicit fear in zebrafish, but that this reaction can be modulated by alcohol. These findings may pave the way for new methodologies for understanding anxiety and other emotions, as well as substances that alter them.
Maurizio Porfiri, associate professor of mechanical and aerospace engineering at the Polytechnic Institute of New York University (NYU-Poly) and Simone Macrì, a collaborator at the Istituto Superiore di Sanità ...
First experimental signs of a New Physics beyond the Standard Model
2013-07-31
The Standard Model, which has given the most complete explanation up to now of the universe, has gaps, and is unable to explain phenomena like dark matter or gravitational interaction between particles. Physicists are therefore seeking a more fundamental theory that they call "New Physics", but up to now there has been no direct proof of its existence, only indirect observation of dark matter, as deduced, among other things, from the movement of the galaxies.
A team of physicists formed by the professor of Physics at Universitat Autònoma de Barcelona (UAB) Joaquim Matias, ...
Key factors for wireless power transfer
2013-07-31
WASHINGTON D.C., July 31, 2013 -- What happens to a resonant wireless power transfer system in the presence of complex electromagnetic environments, such as metal plates? A team of researchers explored the influences at play in this type of situation, and they describe in the American Institute of Physics' journal AIP Advances how efficient wireless power transfer can indeed be achieved in the presence of metal plates.
The team discovered that resonance frequency matching, alignment of the magnetic field, and impedance matching are the most important factors for efficient ...
LAST 30 PRESS RELEASES:
New data on atmosphere from Earth to the edge of space
Self-destructing vaccine offers enhanced protection against tuberculosis in monkeys
Feeding your good gut bacteria through fiber in diet may boost body against infections
Sustainable building components create a good indoor climate
High levels of disordered eating among young people linked to brain differences
Hydrogen peroxide and the mystery of fruit ripening: ‘Signal messengers’ in plants
T cells’ capability to fully prevent acute viral infections opens new avenues for vaccine development
Study suggests that magma composition drives volcanic tremor
Sea surface temperatures and deeper water temperatures reached a new record high in 2024
Connecting through culture: Understanding its relevance in intercultural lingua franca communication
Men more than three times as likely to die from a brain injury, new US study shows
Tongue cancer organoids reveal secrets of chemotherapy resistance
Applications, limitations, and prospects of different muscle atrophy models in sarcopenia and cachexia research
FIFAWC: A dataset with detailed annotation and rich semantics for group activity recognition
Transfer learning-enhanced physics-informed neural network (TLE-PINN): A breakthrough in melt pool prediction for laser melting
Holistic integrative medicine declaration
Hidden transport pathways in graphene confirmed, paving the way for next-generation device innovation
New Neurology® Open Access journal announced
Gaza: 64,000 deaths due to violence between October 2023 and June 2024, analysis suggests
Study by Sylvester, collaborators highlights global trends in risk factors linked to lung cancer deaths
Oil extraction might have triggered small earthquakes in Surrey
Launch of world’s most significant protein study set to usher in new understanding for medicine
New study from Chapman University reveals rapid return of water from ground to atmosphere through plants
World's darkest and clearest skies at risk from industrial megaproject
UC Irvine-led discovery of new skeletal tissue advances regenerative medicine potential
Pulse oximeters infrequently tested by manufacturers on diverse sets of subjects
Press Registration is open for the 2025 AAN Annual Meeting
New book connects eugenics to Big Tech
Electrifying your workout can boost muscles mass, strength, UTEP study finds
Renewed grant will continue UTIA’s integrated pest management program
[Press-News.org] Georgia Tech uncovers iOS security weaknessesAttackers can compromise your iPhone through chargers and apps