April 16, 2024
Skype iOS App is Vulnerable to Attack That Can Steal Your Address Book [Video]

Skype iOS App is Vulnerable to Attack That Can Steal Your Address Book [Video]

Posted September 20, 2011 at 5:21pm by iClarified
Skype's iOS app is vulnerable to an attack that can compromise your entire address book without you noticing, reports TechCrunch.

AppSec Consulting security researcher Phil Purviance discovered the exploit:

I found that Skype also improperly defines the URI scheme used by the built-in webkit browser for Skype. Usually you will see the scheme set to something like, "about:blank" or "skype-randomtoken", but in this case it is actually set to "file://". This gives an attacker access to the users file system, and an attacker can access any file that the application itself would be able to access.


File system access is partially mitigated by the iOS Application sandbox that Apple has implemented, preventing an attacker from accessing certain sensitive files. However, every iOS application has access to the users AddressBook, and Skype is no exception.


Skype says "We are working hard to fix this reported issue in our next planned release which we hope to roll out imminently. In the meantime we always recommend people exercise caution in only accepting friend requests from people they know and practice common sense internet security as always."

Take a look at the attack being performed in the video below...

Read More [via TechCrunch]



Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (3)
You must login or register to add a comment...
Nobo1
Nobo1 - September 20, 2011 at 8:36pm
Ermm.... Are you feeling alright? Might wana have a lay down.. Feverish delusions can be nasty
Lm
Lm - September 20, 2011 at 7:20pm
Everything to do with apple and ios seems to be shit recently. The downfall is near!
Nobo1
Nobo1 - September 20, 2011 at 7:16pm
Great more bloody apps that have security vulnerability...
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Monterey
Where to Download macOS Ventura
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS