iOS Web Attack Surfaces That Can Crash and Restart Your iPhone, iPad

Advertisement
By Jagmeet Singh | Updated: 17 September 2018 12:30 IST
Highlights
  • A new iOS hack has been found that restarts iOS devices
  • The hack uses all the available resources on the system
  • This brings a kernel panic that ultimately brings a sudden restart

Security researcher Sabri Haddouche has released a proof-of-concept showing the flaw

While Apple is busy in the last-minute preparations of iOS 12, a security researcher has shown a proof-of-concept webpage that uses CSS to crash and restart your iOS-running iPhone or iPad instantly. The same CSS-based hack reportedly also freezes a Safari window once you access it on a Mac. The 15-line Web code snippet that highlights the flaw in Apple's operating system tries to use all the available resources on your iOS device. This causes a kernel panic on the hardware and ultimately brings a sudden restart. In July, ex-NSA security researcher Patrick Wardle spotted a bug that was crashing iOS devices on typing Taiwan in iMessage, Facebook, WhatsApp, or other apps, after receiving the Taiwanese flag emoji. The code pushing the denial of service bug was found to be existed in iOS 11.3, though Apple issued a fix with the iOS 11.4.1 update at a later stage.

Security researcher Sabri Haddouche on Saturday tweeted the URL featuring the proof-of-concept webpage that crashes iOS devices. Haddouche also posted the source code of the webpage on GitHub to detail the force restart flaw. While we were able to replicate the flaw and successfully force restart an iPhone 7 based on the latest iOS 11.4.1 and an iPhone 7 Plus based on the most recent iOS 12 beta, the security researcher says that it affects all the devices running iOS 9.0 and above.

The webpage is said to use all the available resources to cause a kernel panic on the system, causing the smartphone to power cycle off and on to prevent damage to the electronics. The code, based on HTML and CSS, contains numerous <div> tags. The CSS lines instruct the browser to apply a blur effect to the every <div> element on the page, overloading the WebKit renderer. This means you'll experience similar results no matter whether you're using Safari or Firefox on your iPhone or iPad.

Advertisement

Unlike some past iOS hacks that brought crashing cases through iMessage or other messaging apps, the latest case causes the sudden restart once you visit the specific webpage. This makes it less impactful. Also, it is worth noting here that the hack doesn't involve any data loss - it just crashes the system by putting much load on it. As it is only 15 lines of code, it can be planted into seemingly innocent websites, or sent via text message.

Advertisement

Nonetheless, Haddouche said that "anything that renders HTML on iOS is affected" through the flaw, as quoted by TechCrunch. This means the link to the hack can be found on any social media apps such as Facebook and Twitter or could be given through an email or a WhatsApp message. Once you tap that link, your device will freeze for a second then restarts.

TechCrunch reports that Haddouche has already intimated Apple about the hack. It is, however, unclear whether the Cupertino giant will be able to fix the flaw in the upcoming iOS 12 update or through a new iOS 12 point release. Meanwhile, it is recommended to avoid tapping any unknown links on your iOS devices.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: iOS, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO 15 Launched With Snapdragon 8 Elite Gen 5, 50-Megapixel Cameras
  2. iQOO Pad 5e Launched Alongside iQOO Watch GT 2 and iQOO TWS 5
  3. OnePlus 15 Battery Capacity, Charging Speed Teased Days Ahead of Launch
  1. OpenAI to Stop Users From Generating Sora Videos of Celebrities Without Consent After Backlash
  2. Redmi K90 Pro Max Key Features Confirmed; Will Feature 6.9-inch Display, Periscope Telephoto Camera
  3. Microsoft Says Asus Determined Pricing for ROG Xbox Ally Handhelds Based on Features, Other Factors
  4. Anthropic Launches Claude Code on the Web, Lets Users Assign Parallel Coding Tasks
  5. OnePlus 15 Battery Capacity, Charging Speed Teased Ahead of October 27 Launch
  6. Realme GT 8 Colourways Revealed Ahead of Launch; Confirmed to Feature 7,000mAh Battery
  7. iQOO 15 Launched With Snapdragon 8 Elite Gen 5, Three 50-Megapixel Rear Cameras: Price, Specifications
  8. Meta AI App Has Reportedly Gained Popularity With the Vibes Features
  9. iQOO Pad 5e With Snapdragon 8 Gen 3 Chip Launched Alongside iQOO Watch GT 2 and iQOO TWS 5
  10. Apple's iOS 26.1 Beta 4 Adds an Option to Tone Down Liquid Glass Transparency
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.