Apple Removes Potentially Malicious App From Store

A potentially malicious piece of software designed to expose a security flaw in the App Store has been removed by Apple.

Charlie Miller, a hacker and principal research consultant at Accuvant Labs, created Instastock, an app which was designed to look like a stock price tracker, but in reality was capable of exploiting a recent update which allows unapproved code to be added to uninstalled apps.

Growing Threat

The app was approved on September 14 and Miller informed Apple of the bug on October 14 with any device running iOS 4.3 or later being susceptible to the flaw. Miller posted a video showing how he could access victim’s personal data on YouTube and commented, “Until now you could just download everything from the app store and not worry about it being malicious. Now you have no idea what an app might do.”

Apple has since removed the app from the store and ejected Miller from its iOS developer programme, to which he responded angrily on Twitter, “First they give researchers access to developer programs, (although I paid for mine), then they kick them out.”

Miller, who plans to present his research at the SyScan Conference in Taiwan on 17 November, has previous identified a number of security flaws in Apple products.

Thorn in Apple’s side

In 2009 he identified a bug in iPhone’s text messaging system that allowed attackers to take control of devices and earlier this year, he revealed that the batteries used in many Mac laptops are vulnerable to attack, meaning they could be used to run malicious code or even explode.

The App Store had previously been regarded as the safest of the popular mobile platforms with the most serious security threats affecting only those who jailbroke their phones.

In March, Blackberry phones were targeted by a variant of the Zeus banking trojan while Android has recently overtaken Java Micro Edition as the most attacked mobile platform.  However security company Trusteer has warned that five percent of iPhones and Android phones will be infected with malware in 2012.

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Northvolt Mulls US Bankruptcy Protection – Report

Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…

17 hours ago

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

19 hours ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

21 hours ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

2 days ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

2 days ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

2 days ago