iOS MDM Protocol Vulnerability Exposes iPhone, iPad to Attack: Report

Advertisement
By Manish Singh | Updated: 4 April 2016 14:23 IST

Another vulnerability has been found in iOS, Apple's mobile operating system. The mobile device management (MDM) interface for iOS, according to security researchers, can be exploited to gain complete access to the device. Apple insists that it's not a vulnerability, but a social-engineering trick.

Security researchers at Check Point Software Technologies claim that an approach dubbed "SideStepper" can allow an attacker to hijack enterprise management functions by sending a malicious link to the device.

According to the researchers, clicking on that link will give attackers full control of the MDM software, and allow them to push malicious apps to the device as well as make changes to other configuration settings. In other words, MDM software in iOS is susceptible to man-in-the-middle attacks and can be exploited to install malware on non-jailbroken devices. The vulnerability was demonstrated at Black Hat Asia 2016.

Advertisement

The researchers claim that Apple patched a similar vulnerability last year with iOS software update, however, it left one hole. These MDM tools are used by companies to control, and configure their employees' devices. These devices have access to a private app store.

Speaking to Ars Technica, Apple has refuted the claims, adding that it was a social-engineering attack, and per se, not a weakness in iOS. "This is a clear example of a phishing attack that attempts to trick the user installing a configuration profile and then installing an app," a spokesperson for the company told the publication.

"This is not an iOS vulnerability. We've built safeguards into iOS to help warn users of potentially harmful content like this. We also encourage our customers to download from only a trusted source like the App Store and to pay attention to the warnings that we've put in place before they choose to download and install untrusted content."

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. OTT Releases This Week: War 2, Mirai, Sthal, Rambo, Kurukshetra, and More
  2. OxygenOS 16 Design, Features Revealed Ahead of October 16 Debut
  3. Samsung Galaxy M17 5G Launching Today: See Price in India, Specifications
  4. Motorola Edge 70 Global Launch Date, Battery Capacity Confirmed
  5. Xiaomi 17 Series Takes Top Three Spots on AnTuTu V11 Flagship Benchmark
  6. WhatsApp's Liquid Glass Design Update Starts Rolling Out to Some Users
  7. iQOO Pad 5e, Watch GT 2 and TWS 5 to Launch Alongside iQOO 15 on This Date
  8. LinkedIn Now Lets Recruiters See Your Notice Period, Salary Expectations
  9. Oppo Find X9 Series Storage Variants Revealed: See Leaked Hands-On Images
  10. OriginOS 6 Teaser Suggests It Might Resemble This Operating System
  1. YouTube Launches Pilot Which Enables Terminated Creators to Request a New YouTube Channel
  2. Huawei MatePad 12 X (2025) Launched With 144Hz PaperMatte Display, 256GB of Storage
  3. Samsung Galaxy M17 5G Launching Today: Know Price in India, Features, Specifications, and More
  4. James Webb Space Telescope Detects Phosphine on Brown Dwarf Wolf 1130C
  5. ‘FlyingToolbox’ Drone System Achieves Sub-Centimeter Accuracy in Mid-Air Tool Exchange
  6. James Webb Telescope Spots Evidence of a Black Hole Carving a Massive Scar Through a Galaxy
  7. Raj Tarun’s Chiranjeeva Premieres on Aha Video This November
  8. Bomb (2025) OTT Release Date: When and Where to Watch This Thrilling Telugu Movie Online?
  9. UK Ends Four-Year Ban on Crypto ETNs as FCA Expands Retail Access
  10. Nobody 2 Now Available for Rent on Prime Video: Everything You Need to Know About Bob Odenkirk’s Action Sequel
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.