
@0xcharlie Discovers iOS Code Signing Security Flaw
Posted November 8, 2011 at 12:31am by iClarified
Charlie Miller, a popular hacker known as 0xcharlie, has discovered a security flaw in the code signing of iOS apps and subsequently been terminated from the iOS developer program.
Forbes reports that at the SysCan conference in Taiwan next week, Miller plans to present a method that exploits a flaw in Apple's restrictions on code signing on iOS devices, the security measure that allows only Apple-approved commands to run in an iPhone or iPad's memory. Using his methodand Miller has already planted a sleeper app in Apple's App Store to demonstrate the trickan app can phone home to a remote computer that downloads new unapproved commands onto the device and executes them at will, including stealing the user's photos, reading contacts, making the phone vibrate or play sounds, or otherwise repurposing normal iOS app functions for malicious ends.
Miller demonstrates the bug in the video posted below. Two hours after linking the Forbes article, he tweeted that Apple had removed his sleeper app and kicked him out of the iOS developer program.
OMG, Apple just kicked me out of the iOS Developer program. That's so rude!
First they give researcher's access to developer programs, (although I paid for mine) then they kick them out.. for doing research. Me angry
dunno, letter of termination. Sounds permenant. feels heavy handed, I miss Steve.
Read More [via Josh]
Forbes reports that at the SysCan conference in Taiwan next week, Miller plans to present a method that exploits a flaw in Apple's restrictions on code signing on iOS devices, the security measure that allows only Apple-approved commands to run in an iPhone or iPad's memory. Using his methodand Miller has already planted a sleeper app in Apple's App Store to demonstrate the trickan app can phone home to a remote computer that downloads new unapproved commands onto the device and executes them at will, including stealing the user's photos, reading contacts, making the phone vibrate or play sounds, or otherwise repurposing normal iOS app functions for malicious ends.
Miller demonstrates the bug in the video posted below. Two hours after linking the Forbes article, he tweeted that Apple had removed his sleeper app and kicked him out of the iOS developer program.
OMG, Apple just kicked me out of the iOS Developer program. That's so rude!
First they give researcher's access to developer programs, (although I paid for mine) then they kick them out.. for doing research. Me angry
dunno, letter of termination. Sounds permenant. feels heavy handed, I miss Steve.
Read More [via Josh]

![Apple Seeds tvOS 26.2 Release Candidate 2 to Developers [Download] Apple Seeds tvOS 26.2 Release Candidate 2 to Developers [Download]](/images/news/99251/99251/99251-160.jpg)
![Alan Dye's Departure Viewed as 'Best Personnel News at Apple in Decades' [Report] Alan Dye's Departure Viewed as 'Best Personnel News at Apple in Decades' [Report]](/images/news/99247/99247/99247-160.jpg)
![Apple Shares Trailer for 'Tehran' Season 3, Announces Season 4 Renewal [Video] Apple Shares Trailer for 'Tehran' Season 3, Announces Season 4 Renewal [Video]](/images/news/99244/99244/99244-160.jpg)






![Final Cyber Monday Deals: M4 MacBook Air for $749, Beats, Sonos, and More [List] Final Cyber Monday Deals: M4 MacBook Air for $749, Beats, Sonos, and More [List]](/images/news/99203/99203/99203-160.jpg)
![iPad mini 7 Falls to New All-Time Low of $349 [Cyber Monday 2025] iPad mini 7 Falls to New All-Time Low of $349 [Cyber Monday 2025]](/images/news/99197/99197/99197-160.jpg)
![Apple Watch Series 11 Drops to New All-Time Low Price of $329 [Cyber Monday 2025] Apple Watch Series 11 Drops to New All-Time Low Price of $329 [Cyber Monday 2025]](/images/news/99195/99195/99195-160.jpg)

![Apple Watch Ultra 3 Drops to New All-Time Low of $679 [Deal] Apple Watch Ultra 3 Drops to New All-Time Low of $679 [Deal]](/images/news/99189/99189/99189-160.jpg)