Thursday, May 28, 2015
A text message to reboot your iPhone
An individual noticed on Tuesday that his iPhone rebooted after receiving an unusual text message. He posted a question about it on Reddit, and word quickly spread. The British technology publication The Register has a nice write-up on what it actually happening; the simple description is this:
When your iPhone attempts to display certain Unicode text (i.e. text using some international character sets), it triggers a flaw in the text processing library, causing the active app to crash. If that app is a core part of the operating system, that crashes the phone, causing a reboot.
Receiving an SMS message, or possibly a Twitter DM, causes the message to be shown in a "notification," a message preview on the lock screen or the top of the screen. Notifications are part of the operating system core, thus crashing the phone.
It doesn't damage the phone permanently, and it doesn't give an attacker control over your phone, so in the long run it's a pretty mild problem. In the short term though, lots of middle school kids (and middle schoolers at heart!) are pranking one another or their parents by sending an SMS message.
Apple has not released an update to fix this, though they have acknowledged the problem. A temporary solution is to disable notification previews. From the iOS "Settings" menu, select "Notifications", then "Messages," and set "Show Previews" to "Off."
This will prevent iMessages from displaying SMS messages previews in the notifications panel or lock screen and crashing the phone. It won't keep the iMessages app itself from crashing if you open a pranked message though. For that, you'll need the offending sender to send you another message, pushing the exploit string off the top of the list; or send yourself a message from another device or app (i.e. send yourself an image using the photo app instead of the iMessage app).
Do you have something to add? A question you'd like answered? Think I'm out of my mind? Join the conversation below, reach out by email at david (at) securityforrealpeople.com, or hit me up on Twitter at @dnlongen
Apple releases iOS 9.3.5 to block a sophisticated iPhone spy techniqu
Updated 2 September: It turns out that the same vulnerabilities exist in OS X for MacBooks and iMacs, and can be used t ...
Random musings from a discussion with MAD Security's Mike Murray
I had a fascinating discussion with Mike Murray, principal at MAD Security, yesterday at a local ISSA chapter meeting. In h ...
Stranger than fiction: the week's security news
I love science fiction. I enjoy sarcastic fictional news such as "The Onion." I even enjoy watching CSI:Cyber desp ...

Gnome in Your Home Part Two: Firmware Analysis
This is one of a multi-part series describing my approach to solving the 2015 SANS Holiday Hacking Challenge; watch Secu ...

Lessons from CSI:Cyber
The CSI: franchise has been a very successful television endeavor, combining entertainment with a view into how forensic s ...