iOS MDM Protocol Vulnerability Exposes iPhone, iPad to Attack: Report

Advertisement
By Manish Singh | Updated: 4 April 2016 14:23 IST

Another vulnerability has been found in iOS, Apple's mobile operating system. The mobile device management (MDM) interface for iOS, according to security researchers, can be exploited to gain complete access to the device. Apple insists that it's not a vulnerability, but a social-engineering trick.

Security researchers at Check Point Software Technologies claim that an approach dubbed "SideStepper" can allow an attacker to hijack enterprise management functions by sending a malicious link to the device.

According to the researchers, clicking on that link will give attackers full control of the MDM software, and allow them to push malicious apps to the device as well as make changes to other configuration settings. In other words, MDM software in iOS is susceptible to man-in-the-middle attacks and can be exploited to install malware on non-jailbroken devices. The vulnerability was demonstrated at Black Hat Asia 2016.

Advertisement

The researchers claim that Apple patched a similar vulnerability last year with iOS software update, however, it left one hole. These MDM tools are used by companies to control, and configure their employees' devices. These devices have access to a private app store.

Advertisement

Speaking to Ars Technica, Apple has refuted the claims, adding that it was a social-engineering attack, and per se, not a weakness in iOS. "This is a clear example of a phishing attack that attempts to trick the user installing a configuration profile and then installing an app," a spokesperson for the company told the publication.

"This is not an iOS vulnerability. We've built safeguards into iOS to help warn users of potentially harmful content like this. We also encourage our customers to download from only a trusted source like the App Store and to pay attention to the warnings that we've put in place before they choose to download and install untrusted content."

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Starlink Will Offer Unlimited Satellite Internet in India at This Price
  2. Motorola Edge 70 With 5.99mm Slim Profile Will Launch in India on This Date
  3. OnePlus 15R Roundup: Price in India, Specs and Everything We Know So Far
  4. Jolla Phone Launched With 5,500mAh Replaceable Battery, Sailfish OS 5
  5. Airtel Partners With Google to Launch RCS Messaging in India
  6. Vivo S50, Vivo S50 Pro Mini Set to Launch on This Date
  7. Nothing Halts Android 16 Rollout to Implement 'Urgent' Fix
  8. Realme Narzo 90 Series 5G India Launch Announced
  9. 'High' Risk Vulnerabilities Discovered in Google Chrome and Edge Browsers
  10. iPhone 16 Deal Alert: Get It for Just Rs 65,900 Effective Price
  1. Xiaomi 17 Global Variant Listed on Geekbench, Tipped to Launch in India by February 2026
  2. James Gunn's Superman to Release on JioHotstar on December 11: What You Need to Know
  3. The Boys Season 5 OTT Release Date: When and Where to Watch the Final Season Online?
  4. The Strangers Chapter 2 Now Available on Rent on Amazon Prime Video, Apple TV, and More
  5. Meta Acquires AI Wearables Startup Limitless, Could Expand Its Hardware Offerings
  6. Airtel Reportedly Partners With Google to Launch RCS Messaging for Users in India
  7. Jolla Phone Launched With 5,500mAh Replaceable Battery, Linux-Based Sailfish OS 5: Price, Availability, Features
  8. CERT-In Warns Chrome, Edge Users of ‘High’ Risk Vulnerabilities on Windows, macOS, and Linux
  9. Coinbase Reopens Registrations in India, Plans Fiat On-Ramp in 2026
  10. Google Could Soon Release Nano Banana 2 Flash AI Model: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.