At the RSA 2015 conference, Adi Sharabani and Yair Amit (Skycure team) revealed a zero-day vulnerability in iOS 8 that, when exploited by a malicious wireless hotspot, can repeatedly crash all Apple devices, namely iPhones, iPads, and iPods.
The researchers named the attack “No iOS Zone,” and it can render all iOS devices vulnerable and unstable, or even completely unusable by causing constant reboots.
“Anyone can create a Wi-Fi hotspot from any router and force you to connect to their network. They can then manipulate the traffic to cause the operating system to crash,” Sharabani said at the RSA security conference today in San Francisco.
“There’s nothing you can do about it, except maybe to avoid the attackers. It’s not a regular denial-of-service where you just can’t use your Wi-Fi – it’s a denial-of-service where you won’t be able to use your device, even in offline mode.”.
The denial-of-service attack is triggered by handling SSL certificates sent to iOS devices over Wi-Fi, and the specially crafted data will cause the applications to crash or possibly the operating system itself.
"Given that the vulnerability has not been fully confirmed, and has not yet been fixed, we have decided not to provide additional technical details, to be sure that iOS users are not left exposed to the Exploit," the researchers said.
Watch the presentation videos
https://www.youtube.com/watch?v=PmgI0LaFYLA
https://www.youtube.com/watch?v=i2tYdmOQisA
You can download the presentation of the attack in PDF format from the official RSA 2015 .
