HomeAboutContact
News & Discussion » Beware of Web Dialing via iPhone’s Safari Browser « Next post  |  Previous post »
Recent Articles
Latest Comments
Kindra - Sep 6, 2008 4:07 pm
Henry: Yes, you can get iPhone glass for cheap, but guess what?... (View comment)
» iPhone Glass Cracked After Drop: Will it Cost Me?
Jordan Dobson - Sep 5, 2008 8:35 pm
I’ve also put together a simpler and sexier... (View comment)
» How to Add Speed Dial Icons to iPhone’s Home Screen
Henry - Sep 5, 2008 7:55 pm
well i feel sorry for all you guys the iphone glass just cost... (View comment)
» iPhone Glass Cracked After Drop: Will it Cost Me?
Oxykisses - Sep 5, 2008 3:24 pm
I wanted to turn the preview off just bc theres so... (View comment)
» How Has iPhone’s SMS Preview Gotten You Into Trouble?
Kimmy - Sep 5, 2008 9:49 am
Here is my solution, only works with jailbroken iPhones... (View comment)
» iPhone Text Message Privacy: How to Turn off SMS Preview
Popular Articles

Subscribe to blog

Get email updates

About Chris

I'm not an iPhone news company. I'm just an iPhone owner with a critical eye. Read more.

Sections
Photostream
via flickr
More of my photos
Jul 17, 2007 | By Chris | Tags: ,
RSS Sick of the same old regurgitated iPhone news? Subscribe to Apple iPhone Review for fresh insights, accessory reviews, and iPhone how-to's.

iPhone’s web dialing feature — that is, the ability to tap a phone number from within the Safari browser in order to call it — poses a potential security problem, warned research firm SPI Labs.

In a blog post from the SPI Laboratory, one researcher said iPhone’s web dialing feature could “be exploited by attackers to perform various attacks,” including:

  • Redirecting phone calls placed by the user to different phone numbers of the attacker’s choosing
  • Tracking phone calls placed by the user
  • Manipulating the phone to place a call without the user accepting the confirmation dialog
  • Placing the phone into an infinite loop of attempting calls, through which the only escape is to turn off the phone
  • Preventing the phone from dialing

I personally love the web dialing feature. SPI Labs said it is working with Apple to resolve the issue.

Commenters on the SPI blog pointed out that other smartphones have a similar web dialing feature, which is seldom exploited. SPI responded by saying that it had only tested the iPhone.

Be the First to Comment

« iPhone AppleCare: $69 a Year How to Get Album Art for Your... »