iPhone's Safari dialing feature can be hacked
Intended to be a convenience, the unique dialing feature included in the iPhone version of the Safari browser might soon become a nightmare.
SPI Labs' lead researcher Billy Hoffman says that the feature that is designed to dial any number displayed on a Web page after a user taps it is subject to various attacks, including cross-site scripting and drive-by downloads. This issue was first reported to Apple on July 6, but Hoffman believes the "unique urgency" and its potential to affect a large number of people warranted public disclosure.
Potential uses of this vulnerability cited by Hoffman … Read more