At the RSA 2015 conference, Adi Sharabani and Yair Amit (Skycure team) revealed a zero-day vulnerability in iOS 8 that, when exploited by a malicious wireless hotspot, can repeatedly crash all Apple devices, namely iPhones, iPads, and iPods.
The researchers named the attack «No iOS Zone», and it can make all iOS devices vulnerable and unstable or even completely useless by causing continuous reboots.
"Anyone can create a Wi-Fi hotspot from any router and force you to connect to their network. They can then manipulate the traffic to cause the operating system to crash," Sharabani said at the RSA 2015 security conference today in San Francisco.
“There is nothing you can do about “this, except perhaps avoid the attackers. It is not a typical denial-of-service where you simply cannot use your Wi‑Fi – it is a denial-of-service that you will not be able to use your device, even in offline mode”.
The denial-of-service attack is triggered by handling SSL certificates sent to iOS devices over Wi-Fi, and the specially crafted data will cause the applications to crash or possibly the operating system itself.
«Given that the vulnerability has not been fully verified, and has not yet been determined, we have decided not to provide additional technical details, to ensure that iOS users will not remain exposed to the Exploit,» said the researchers.
You can download the presentation of the attack in PDF format from the official RSA 2015 page .
Source: secnews.gr

