How To Hijack ‘Every iPhone In The World’
On Thursday, two researchers plan to reveal an unpatched iPhone bug that could virally infect phones via SMS. — If you receive a text message on your iPhone any time after Thursday afternoon containing only a single square character, Charlie Miller would suggest you turn the device off.
Context & Ripple Effects
This lands days after Charlie Miller again proved his credentials at CanSecWest, where he broke into a fully patched MacBook via Safari at Pwn2Own in March — following his 2008 two-minute MacBook Air win there. The difference this time is scale: instead of luring a victim to a malicious page, the claimed vector is a single inbound SMS containing one square character, meaning no user interaction at all.
That puts Apple in an awkward spot ahead of Thursday's presentation: a flaw that spreads virally phone-to-phone over carrier networks, disclosed before a fix exists, touches every iPhone rather than just careless users — echoing how [[a:|iPhone traffic]] had already overwhelmed dozens of Wi-Fi access points at Duke University back in 2007, showing how one device behavior can cascade across shared infrastructure.
First-order effects
- Apple faces pressure to ship an emergency SMS-stack patch immediately after Thursday's disclosure, since any iPhone receiving the crafted message is exposed with zero clicks required.
- Miller's track record — two consecutive Pwn2Own MacBook wins in 2008 and 2009 — gives the claim immediate credibility, pushing carriers and enterprises to treat inbound texts as a threat channel rather than trusted notifications.
Second-order effects
- Rival handset makers will have to audit their own SMS parsing code once the technique is public, because the vulnerability class lives in the protocol stack most phones share, not in Apple's implementation alone.
- Wireless carriers get pulled into the security conversation for the first time in this arc, since the attack rides their signaling infrastructure and they cannot filter it at the handset level.
Third-order effects
- If the pattern holds — researchers demonstrating phone-to-phone viral exploits at hacker conferences — mobile OS vendors move toward faster coordinated-disclosure patching, and carrier-grade messaging shifts from assumed-safe plumbing to a first-class attack surface.
- A successful demo would mark the point where smartphones stop being treated as PCs with a phone bolted on and start being treated as networked appliances whose radio channels need the same hardening discipline desktop software went through in the 2000s.
The trend: Smartphone security is shifting from browser-and-desktop exploit research toward carrier-side messaging channels, with conference disclosures forcing handset makers and carriers into a faster joint patching rhythm.