What you need to know about the CoreText exploit that can crash iOS and OS X apps
An exploit in CoreText, the font rendering framework in current, publicly available versions of iOS and OS X, has been discovered that can cause apps to crash. According to habrahabr.ru, it can be remotely triggered via SMS or iMessage, Safari, and even the ESSID of a Wi-Fi network when scanning for and displaying them. Our security editor, Nick Arnott, has been looking into it this morning and shared the following:
- OS X 10.8.4 - Receiving the string in iMessage will crash it. You can restart iMessage without it crashing and delete the conversation.
- OS X Mavericks - Doesn't crash Messages or Safari.
- iOS 7 - Doesn't crash Messages or Safari.
- iOS 6 - System crashes after receiving message. After rebooting, Messages will crash every time you try to open it.
Here's his workaround for iOS 6:
Apple is apparently aware of the exploit and is rumored to have already fixed it in Mavericks as well as iOS 7. There's also reportedly a jailbreak patch for it.
In the meantime, just like the previous FIle:/// exploit that caused crashes on OS X, it probably won't amount to much cause for real-world concern. Unless you have friends who are complete dicks and would delight in messing with you this way, or unless and until there are wide spread reports of this exploit turning up in the wild, it's probably not worth spending much time worrying about.
Nick Arnott contributed significantly to this article.
Source: habrahabr.ru
Master your iPhone in minutes
iMore offers spot-on advice and guidance from our team of experts, with decades of Apple device experience to lean on. Learn more with iMore!
Rene Ritchie is one of the most respected Apple analysts in the business, reaching a combined audience of over 40 million readers a month. His YouTube channel, Vector, has over 90 thousand subscribers and 14 million views and his podcasts, including Debug, have been downloaded over 20 million times. He also regularly co-hosts MacBreak Weekly for the TWiT network and co-hosted CES Live! and Talk Mobile. Based in Montreal, Rene is a former director of product marketing, web developer, and graphic designer. He's authored several books and appeared on numerous television and radio segments to discuss Apple and the technology industry. When not working, he likes to cook, grapple, and spend time with his friends and family.