It had to happen. With so many units sold it was only a matter of time before someone took apart the security on the One Phone To Rule Them All.

The exploits come in two flavors and both require that you visit a site with malicious code. The first allows an assailant to snoop around on the contact information stored in your phone, the second allows them to actually make calls and send SMS messages. Here is an excerpt from the CNET article.

iPhone Vulnerabilities

‘One of the exploits requires the Safari browser to surf to a maliciously coded Web site. Once there, personal data, SMS text files, contact information, call history, passwords, e-mail, browser history, and voice mail information could be obtained by a remote attacker.

A second exploit developed by the researchers caused the iPhone to make a system sound and vibrate for a second after visiting a maliciously coded Web site. The same exploit could also dial a phone number, send a text message, or turn on the microphone to eavesdrop remotely on conversations within the room.

Web 2.0 Roundup

Keep an eye out for more to arrive on this front. Having a phone with internet access as strongly integrated as the iPhone leaves the device open to these sorts of exploits. Hopefully Apple reacts quickly to fix these problems.

[Be sure to subscribe to the RSS feed before leaving]