Never trust SMS: iOS text spoofing
I mentioned it on twitter a few days ago, I found a flaw in iOS that I consider to be severe, while it does not involve code execution. I am pretty confident that other security researchers already know about this hole, and I fear some pirates as well.
Context & Ripple Effects
Security researcher pod2g has published details of what he calls a severe iOS flaw that lets an attacker spoof the sender of an SMS message — no code execution required, just a crafted payload that makes a text appear to come from any number the victim knows. He disclosed it on his blog after flagging it on Twitter days earlier, saying he suspects other researchers and possibly malicious actors already knew.
The disclosure lands on a long arc of iPhone security embarrassments: SPI Labs warned users away from an iPhone feature back in July 2007 (SPI Labs advises avoiding iPhone feature), and Forbes ran a piece in July 2009 on how to hijack every iPhone in the world (How To Hijack Every iPhone In The World). What makes this one travel is its breadth — Redmond Pie, PC Magazine, Engadget, MacRumors, ZDNet, AppleInsider, Ars Technica and VentureBeat all picked it up within a day — and its target: not the OS kernel but the trust users place in the sender line of a text message.
First-order effects
- iPhone users lose a working trust signal: any SMS on a vulnerable device can be made to appear from a bank, a contact, or a service, enabling phishing without any malware on the phone.
- Apple faces immediate public pressure to ship a fix, with pod2g's severity framing ('severe', though non-executing) and eight-outlet pickup making quiet patching difficult.
Second-order effects
- Any service relying on SMS as an identity or two-factor channel — banks, payment confirmations, account resets — inherits the spoofing risk on iOS, pushing those vendors to weigh app-based or authenticated messaging alternatives.
- Rival platforms get a comparative-security talking point, and Apple's response will be judged against how quickly it patches versus how it frames the threat.
Third-order effects
- If display-layer spoofing keeps resurfacing across mobile platforms, the industry's implicit contract — that the sender field shown to a user is trustworthy — breaks down, accelerating migration of sensitive communication onto authenticated, platform-controlled channels like iMessage over raw SMS.
- Independent researcher disclosure via blogs and Twitter, rather than coordinated vendor disclosure, is becoming the default path for consumer-platform flaws, forcing vendors to build faster public-response machinery.
The trend: Mobile messaging trust is migrating from unauthenticated SMS toward platform-controlled authenticated channels, with independent researchers forcing the pace by exposing spoofing-class flaws.