Nov
09
2010

Malicious Websites Can Initiate Skype Calls On iOS

An anonymous reader writes “In this article, security researcher Nitesh Dhanjani shows how iOS insecurely launches third-party apps via registered URL handlers. Malicious websites can abuse this to launch arbitrary applications, such as getting the Skype.app to make arbitrary phone calls without asking the user. Dhanjani ‘contacted Apple’s security team to discuss this behavior, and their stance is that the onus is on the third-party applications (such as Skype in this case) to ask the user for authorization before performing the transaction.’ He also discusses what developers of iOS apps can do to design their software securely and what Apple can do to help out.”

Read more of this story at Slashdot.


Go here to see the original:
Malicious Websites Can Initiate Skype Calls On iOS

Written by Staff in: Slashdot | Tags: ,

No Comments »

RSS feed for comments on this post. TrackBack URL


Leave a Reply

You must be logged in to post a comment.

adsense

Cool-O-Rama: News for Geeks