iOS Web Attack Surfaces That Can Crash and Restart Your iPhone, iPad

Advertisement
By Jagmeet Singh | Updated: 17 September 2018 12:30 IST
Highlights
  • A new iOS hack has been found that restarts iOS devices
  • The hack uses all the available resources on the system
  • This brings a kernel panic that ultimately brings a sudden restart

Security researcher Sabri Haddouche has released a proof-of-concept showing the flaw

While Apple is busy in the last-minute preparations of iOS 12, a security researcher has shown a proof-of-concept webpage that uses CSS to crash and restart your iOS-running iPhone or iPad instantly. The same CSS-based hack reportedly also freezes a Safari window once you access it on a Mac. The 15-line Web code snippet that highlights the flaw in Apple's operating system tries to use all the available resources on your iOS device. This causes a kernel panic on the hardware and ultimately brings a sudden restart. In July, ex-NSA security researcher Patrick Wardle spotted a bug that was crashing iOS devices on typing Taiwan in iMessage, Facebook, WhatsApp, or other apps, after receiving the Taiwanese flag emoji. The code pushing the denial of service bug was found to be existed in iOS 11.3, though Apple issued a fix with the iOS 11.4.1 update at a later stage.

Security researcher Sabri Haddouche on Saturday tweeted the URL featuring the proof-of-concept webpage that crashes iOS devices. Haddouche also posted the source code of the webpage on GitHub to detail the force restart flaw. While we were able to replicate the flaw and successfully force restart an iPhone 7 based on the latest iOS 11.4.1 and an iPhone 7 Plus based on the most recent iOS 12 beta, the security researcher says that it affects all the devices running iOS 9.0 and above.

Advertisement

The webpage is said to use all the available resources to cause a kernel panic on the system, causing the smartphone to power cycle off and on to prevent damage to the electronics. The code, based on HTML and CSS, contains numerous <div> tags. The CSS lines instruct the browser to apply a blur effect to the every <div> element on the page, overloading the WebKit renderer. This means you'll experience similar results no matter whether you're using Safari or Firefox on your iPhone or iPad.

Unlike some past iOS hacks that brought crashing cases through iMessage or other messaging apps, the latest case causes the sudden restart once you visit the specific webpage. This makes it less impactful. Also, it is worth noting here that the hack doesn't involve any data loss - it just crashes the system by putting much load on it. As it is only 15 lines of code, it can be planted into seemingly innocent websites, or sent via text message.

Advertisement

Nonetheless, Haddouche said that "anything that renders HTML on iOS is affected" through the flaw, as quoted by TechCrunch. This means the link to the hack can be found on any social media apps such as Facebook and Twitter or could be given through an email or a WhatsApp message. Once you tap that link, your device will freeze for a second then restarts.

TechCrunch reports that Haddouche has already intimated Apple about the hack. It is, however, unclear whether the Cupertino giant will be able to fix the flaw in the upcoming iOS 12 update or through a new iOS 12 point release. Meanwhile, it is recommended to avoid tapping any unknown links on your iOS devices.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: iOS, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Demon Slayer: Infinity Castle Movie OTT Release Date: When and Where to Watch it Online?
  2. OnePlus Nord 6 Launched in India With 9,000mAh Battery at This Price
  3. Fujifilm Launches XT-30 III Mirrorless Camera in India at This Price
  4. Redmi Note 15 SE 5G With 5,800mAh Battery Goes on Sale in India: See Offers
  5. Here's When the Realme Buds T500 Pro Will Launch in India
  6. Lenovo Launches New IdeaPad 5 2-in-1 and Yoga Series Laptops in India
  7. OnePlus Nord 6 vs Redmi Note 15 Pro+ 5G vs Nothing Phone 4a Pro Compared
  8. Vivo X300 FE Launch Timeline Leaked Alongside These Three Colourways
  9. Best Laser Printers With Automatic Duplex Printing in India
  10. Apple's First Foldable Is Reportedly on Track to Launch Later This Year
  1. Google Chrome Updated With Vertical Tabs Feature and Full Page Reading Mode
  2. Apple’s First Foldable Reportedly on Track for September Launch Despite Claims of Production Delays
  3. Google Improves AI-Powered Shopping Experience in India With Gemini, Search, and Circle to Search Updates
  4. Motorola Edge 60 Fusion, Moto G57 Power and G35 Price in India Hiked, Tipster Claims
  5. Rubin Observatory Discovers Over 11,000 Asteroids Within Weeks of Imaging
  6. OnePlus Nord 6 Launched in India With Snapdragon 8s Gen 4 SoC, 9,000mAh Battery: Price, Specifications
  7. Sony Reportedly Preparing 'The ColleXion' 1000X-Series Headphones; Price, Launch Date Leaked
  8. Vivo X500 Pro Max Tipped to Feature Next-Generation Sony Camera Sensor
  9. Argentine Banks Reportedly Begin Testing JPMorgan’s JPM Coin for Faster Settlements
  10. Solana Foundation Launches STRIDE Network to Strengthen DeFi Security
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.