SPI Labs advises avoiding iPhone feature
The Apple iPhone's Safari web browser has a special feature that allows the user to dial any phone number displayed on a web page simply by tapping the number. SPI Labs has discovered that this feature can be exploited by attackers to perform various attacks, including:
Context & Ripple Effects
Weeks after the iPhone's June 2007 launch, security researchers are probing the device faster than most buyers expected. SPI Labs' finding targets a signature convenience — tapping any phone number shown in Safari to place a call — and turns it into an attack vector, with the firm publicly advising users to steer clear of the feature.
The disclosure lands amid a rough first month for the device on networks: [[relationships confirm]] iPhone traffic knocked out dozens of Wi-Fi access points at Duke University, so this is the second documented case in as many weeks of an iPhone-specific behavior forcing administrators or users to change how they use the phone.
First-order effects
- iPhone owners following SPI Labs' advice must manually avoid tapping numbers on unfamiliar web pages, giving up one of the device's headline browser conveniences until Apple responds.
- Apple takes an early reputational hit on its security posture: a researcher-published advisory about a shipping feature, not a theoretical flaw, days into the product's life.
Second-order effects
- IT departments evaluating the iPhone for business use now weigh researcher disclosures like this alongside network incidents such as the Duke University Wi-Fi outages, raising the bar for corporate adoption of a consumer device.
- Rival handset makers can market their phones' browser-telephony integrations against Apple's, using published advisories as competitive ammunition during the iPhone's launch window.
Third-order effects
- If researchers keep finding exploitable seams between web content and phone functions, smartphone security will have to treat every convenience that bridges the browser and the dialer as an attack surface requiring explicit user consent controls.
- Independent labs like SPI Labs establishing a pattern of publishing launch-window findings would push device makers toward faster patch pipelines and bug-bounty-style engagement rather than silence.
The trend: Smartphone launches are entering a cycle where independent security researchers probe headline conveniences within weeks of release, making browser-to-telephony integration an early template for mobile attack surface.