Security researcher Andreas Kurtz has discovered a very dangerous flaw in Apple's mobile operating system ( iOS ). The vulnerability has to do with email encryption. Kurtz says Apple is aware of his findings, having informed them immediately, but the company has not fixed the problem.
Sometime last month, Kurtz noticed that email attachments within the company's Mail app were not being protected by Apple. The company says it uses all necessary security mechanisms to protect data. Kurtz confirmed the vulnerability using an iPhone 4 with the latest firmware and an IMAP account.
Kurtz says, "I verified this issue with an iPhone 4 (GSM) updated to the latest iOS versions (7.1 and 7.1.1). I created an IMAP email account to test emails and attachments."
"Then, I shut down the device and managed to access the file system, using the well-known techniques DFU mode, custom ramdisk, SSH over usbmux. Finally, I mounted the iOS data partition and browsed to the actual email folder of the device. Through this folder, I had access to all the contents that had no encryption or any restriction."
The hacker was able to compromise the latest version of the iPhone, as well as the second-generation iPad, which was running iOS 7.0.4. Despite his warnings to Apple, the Cupertino company did not fix the bug with the release of iOS 7.1.1. Kurtz even claims that the company knew about the bug before he reported it to them.
“I reported the bug to Apple,” Kurtz says. “They said they were aware of it, but they didn’t say when they would fix it. Given how long iOS 7 has been available and the severity of the email attachment vulnerability, I expected a patch pretty quickly. Unfortunately, even today with iOS 7.1.1, the issue is still not fixed, leaving users at risk.”
The security expert offers a solution for users concerned that their data could end up in the wrong hands:
"As a temporary solution, concerned users can disable mail synchronization (at least on devices that the bootrom can exploit and allows it)," Kurtz says.
Source: secnews.gr

