Address bar spoofing exploit found for iPhone, iPad Safari in iOS 5.1

iOS 5.1 Exploit With the amount of iOS devices out there in the world these days, the amount of individuals looking to exploit Apple's offerings is growing.

A new security vulnerability has now been exposed pertaining to how Apple's Safari web browser handles site names entered into the address bar. The exploit, discovered by David Vieira-Kurz of MajorSecurity, involves spoofing (faking) the name of the site the user thinks they are going to in Safari while secretly redirecting them to a different, potentially malicious website without their knowledge.

The vulnerability has been reproduced on every device running iOS 5.1 including the iPhone 4, iPhone 4S, iPad 2 ,and the new iPad. Given the reproducible results, the Dutch Ministry of Security and Justice has issued a warning.

A proof of concept has been provided by Vieira-Kurz and the results have been acknowledged by Apple as far back as March 3rd. That said; it stands to reason that an update from Apple is being worked on to close the hole.

If you're looking to test out the proof of concept yourself, you can visit the Vieira-Kurz website in the source link below. If you test it, you can see how simply pushing the demo button will load a new site but the address bar would have you believe it's still

Until an update is pushed from Apple, ensure you do not go clicking on any random links you don't trust and also avoid offering up any personal details on sites you're not 100% sure about. When it doubt, type in the address yourself rather than clicking a link to better make sure you're going to the right place. These common safety measurements for the internet, but certainly worth repeating with this new found exploit now known to the masses.

Source: The Next Web; Via - Vieira-Kurz

Chris Parsons

Editor-at-Large at Mobile Nations, gadget junkie, energy drinker, ranter.

There are 21 comments. Add yours.

Inappropriate Response says:

yeah , I've been waiting for this feature for a while now.

I says:

Are your base are belong to ios!

GinoDotCom says:

This is truly a scary exploit! I relay heavily on what the safari browser address bar tells me. At least I used to!
Scary shyt

CycloneFW says:

Thankfully, if you follow the proof of concept, you can see how the put text above the page and framed in the apple site. If you hit reload, what is actually in the address bar it will refresh to the real site. Still scary but at least if you are concerned, you just have to hit refresh.

johna says:

Look for the green lock for secure sites. This tells you that the website is real. It's a feature of most modern browsers.

keyboard case says:

nickpthemft says:

Too bad that it isn't a browser-based userland exploit for something similar to

dan says:

dear imore,
the word "amount" is for things you can't count -- like air, sugar, and gas. for things you can count, the word is "number."
so, it's "the number of iOS devices" and "the number of individuals..." :-)

mark says:

And amount is for money, which also can't be counted. :) A better way to phrase the rule is that "amount" is for things that properly go with the question "how much?" and "number" is for things that go with "How many?"

Anti_kimchi says:

Ahhh, Countable and uncountable
Fewer android devices were sold than iPhones. (That's right! FEWER not Less)
I enjoy android less than IOS.

