Researcher sends malicious app into Apple App Store
Sneaking past Apple's App Store proves successful, but the researcher who discovers the flaw is thrown off the iOS developer programme.
A software hole in Apple's iPhone and iPad devices may permit developers to break through the App Store gates and control the device.
Security researcher Charlie Miller discovered the flaw, allowing developers to bypass the code signing restrictions and secretly install malware onto Apple devices.
"The flaw I found allows apps in the App Store to download new code and run it even if it's not signed or even if it hasn't been checked by Apple," Miller said in his YouTube clip below.
"Until now you could just download everything from the App Store and not worry about it being malicious. Now you have no idea what an app might do," said Miller.
Miller demonstrated the flaw by using a stock price checking application he created, InstaStock, which was approved even though it contained features to download unapproved code.
The app's code could let a hacker download an address book, view pictures, access other data and even make the phone vibrate.
Despite attempting to highlight security flaws in Apple's systems, because he had broken Apple's App Store rules, Miller was thrown off the iOS developer programme.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Apple just kicked me out of the iOS Developer program. That's so rude," Miller tweeted on Monday. "First they give researcher's access to developer programs, (although I paid for mine) then they kick them out for doing research. Me angry."
"Just found out not only am I kicked out, I can't come back for a year. 1 year suspension," Miller tweeted today.
Apple has now removed the app from its App Store.
-
Dell Technologies World 2026: all the news, updates, and announcements from the Day 1 keynoteKeep up to date with all the news as it happens live from Dell Technologies World 2026 in Las Vegas
-
Hospital cyber attacks are increasingly hitting patient careNews New research shows only 14% are confident they can lose access to health records for 72 hours without risk to patients
-
Anthropic targets vulnerability detection gains with Claude Security public beta — here's what users can expectNews The Claude Mythos developer is aiming for a more limited approach to cyber tooling for public consumption
-
Researchers warn millions of RDP and VNC servers are wide open to exploitationNews Researchers at Forescout spotted millions of RDP and VNC servers exposed online
-
Brace yourselves for a vulnerability explosion, Forescout warnsNews AI advances are helping identify software flaws at record pace and scale, but that's not the good news some would think
-
Ubuntu vulnerability exposes enterprises to root escalation, complete system compromiseNews The high-severity Ubuntu vulnerability allows an unprivileged local attacker to escalate privileges through the interaction of two standard system components
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
Millions of developers could be impacted by flaws in Visual Studio Code extensions – here's what you need to know and how to protect yourselfNews The VS Code vulnerabilities highlight broader IDE security risks, said OX Security
-
CVEs are set to top 50,000 this year, marking a record high – here’s how CISOs and security teams can prepare for a looming onslaughtNews While the CVE figures might be daunting, they won't all be relevant to your organization
-
Microsoft patches six zero-days targeting Windows, Word, and more – here’s what you need to knowNews Patch Tuesday update targets large number of vulnerabilities already being used by attackers