
@0xcharlie Discovers iOS Code Signing Security Flaw
Posted November 8, 2011 at 12:31am by
Shalom Levytam
Charlie Miller, a popular hacker known as 0xcharlie, has discovered a security flaw in the code signing of iOS apps and subsequently been terminated from the iOS developer program.
Forbes reports that at the SysCan conference in Taiwan next week, Miller plans to present a method that exploits a flaw in Apple's restrictions on code signing on iOS devices, the security measure that allows only Apple-approved commands to run in an iPhone or iPad's memory. Using his methodand Miller has already planted a sleeper app in Apple's App Store to demonstrate the trickan app can phone home to a remote computer that downloads new unapproved commands onto the device and executes them at will, including stealing the user's photos, reading contacts, making the phone vibrate or play sounds, or otherwise repurposing normal iOS app functions for malicious ends.
Miller demonstrates the bug in the video posted below. Two hours after linking the Forbes article, he tweeted that Apple had removed his sleeper app and kicked him out of the iOS developer program.
OMG, Apple just kicked me out of the iOS Developer program. That's so rude!
First they give researcher's access to developer programs, (although I paid for mine) then they kick them out.. for doing research. Me angry
dunno, letter of termination. Sounds permenant. feels heavy handed, I miss Steve.
Read More [via Josh]
Forbes reports that at the SysCan conference in Taiwan next week, Miller plans to present a method that exploits a flaw in Apple's restrictions on code signing on iOS devices, the security measure that allows only Apple-approved commands to run in an iPhone or iPad's memory. Using his methodand Miller has already planted a sleeper app in Apple's App Store to demonstrate the trickan app can phone home to a remote computer that downloads new unapproved commands onto the device and executes them at will, including stealing the user's photos, reading contacts, making the phone vibrate or play sounds, or otherwise repurposing normal iOS app functions for malicious ends.
Miller demonstrates the bug in the video posted below. Two hours after linking the Forbes article, he tweeted that Apple had removed his sleeper app and kicked him out of the iOS developer program.
OMG, Apple just kicked me out of the iOS Developer program. That's so rude!
First they give researcher's access to developer programs, (although I paid for mine) then they kick them out.. for doing research. Me angry
dunno, letter of termination. Sounds permenant. feels heavy handed, I miss Steve.
Read More [via Josh]


![TSMC Enters 'Combat Readiness Mode' as 2nm Capacity Fills Up, Apple Secures Early Access [Report] TSMC Enters 'Combat Readiness Mode' as 2nm Capacity Fills Up, Apple Secures Early Access [Report]](/images/news/99826/99826/99826-160.jpg)
![Samsung to Begin Mass Production of Display Panels for First OLED MacBook Pro in May [Report] Samsung to Begin Mass Production of Display Panels for First OLED MacBook Pro in May [Report]](/images/news/99825/99825/99825-160.jpg)






![Beats Powerbeats Pro 2 Drop to $199.95 [Deal] Beats Powerbeats Pro 2 Drop to $199.95 [Deal]](/images/news/99815/99815/99815-160.jpg)
![Apple Watch Series 11 Drops Back to All-Time Low of $299 [Deal] Apple Watch Series 11 Drops Back to All-Time Low of $299 [Deal]](/images/news/99283/99283/99283-160.jpg)
![Apple AirPods 4 With Active Noise Cancellation Drop to $119 [Deal] Apple AirPods 4 With Active Noise Cancellation Drop to $119 [Deal]](/images/news/99794/99794/99794-160.jpg)
![AirPods Pro 3 Return to All-Time Low Price of $199 [Deal] AirPods Pro 3 Return to All-Time Low Price of $199 [Deal]](/images/news/99752/99752/99752-160.jpg)
![Apple's 13-Inch M5 iPad Pro (Silver) Hits New All-Time Low at $1,149.99 [Deal] Apple's 13-Inch M5 iPad Pro (Silver) Hits New All-Time Low at $1,149.99 [Deal]](/images/news/99729/99729/99729-160.jpg)