[ Security Vulnerability ] SpyPhone – trojan for non jailbroken devices

by admin on December 10, 2009

in News,Security Vulnerability


A Swiss iPhone developer has unveiled a new application that is capable of harvesting huge amounts of personal data from iPhones, including data like

  • geolocation data
  • passwords
  • address book entries
  • email accounts information
  • images
  • Safari Browsing history
  • youtube related data
  • keyboard logger, etc

via wmexperts.com

for non jailbroken devices

In oder for , to work, it does not need any exploits or any jailbreaking/firmware modification, attacks in order to access the iPhone’s data. Instead, relies on using the iPhone’s usability and depth of features to its advantage, the app uses the public API exposed by Apple’s SDK. Once an application is on an iPhone, it has unrestricted access to the large amount of the data and settings available on the device. is more like a sitting in your OS silently and stealing data. All of the ’s operations are executed in the background, without the knowledge of the iPhone’s owner, and just like any other , the application can be set to email reports on each infected phone back to the attacker.

Seriot, the application developer, has posted the source code for SpyPhone online. Which increases the risk of the app being used by malicious hackers in their dodgy apps that might end up in the app store.

Any app in the App Store may have this, making it very hard for Apple to eradicate the issue.

Share

{ 1 comment… read it below or add one }

Panama Chiriqui May 13, 2010 at 4:59 am

I am unquestionably bookmarking this web site and sharing it with my friends. You will be getting plenty of visitors to your web site from me!

Reply

Leave a Comment

Previous post:

Next post: