HomeSecurityZero day vulnerability in the Gmail app for iOS

Zero-day vulnerability in Gmail app for iOS

A vulnerability that allows a potential attacker to intercept encrypted communication between the Gmail for iOS devices and Google's server using a man-in-the-middle (MitM) technique has been discovered by security researchers.

The vulnerability lies in the fact that the application does not use the legitimate certificate that validates the connection from the receiving server, a feature called certificate pinning.

The pinning in the certificate for the server should normally be hard-coded to allow information exchange only when it encounters a match on the server side.

Gmail

The Gmail app for iOS devices does not have this feature, and so cybercriminals could use a malicious certificate to impersonate the server through their systems, thus gaining access to information in an unencrypted form.

Researchers from Lacoon mobile security company presented an attack scenario, which involves a man-in-the-middle attack. In the attack, the researchers manage to add an unauthorized CA certificate.

So when the victim runs the Gmail app, all of the app's traffic is under the control of the researchers, giving them access to all communication in plain text.

Google, which is usually very sensitive about security issues in its products, seems to be unable to do much this time. Lacoon mobile security said that it has reported the vulnerability to Google since February 24 and to date no patch has been released.
“The Lacoon research team informed Google about this issue on February 24. Google recognized the flaw and validated it. They told us that they were going to fix it but to this day, the vulnerability still exists,” said Avi Bashan.

 

Source: secnews.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS