Skip to Main Content
PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

Report: Text-Based Exploit in OS X, iOS Causing App Crashes

Jailbreakers are furiously working on patches for an exploit using "a string of Arabic characters" to crash applications on Macs, iPhones, and iPads, 9to5Mac reports.

August 29, 2013
Apple Text Exploit

Jailbreakers are furiously working on a clean patch for an exploitable, text-based bug in Apple's OS X 10.8 and iOS 6 operating systems, which cause application crashes, according to 9to5Mac.

The exploit uses "a string of Arabic characters" to crash applications in the most current versions of Apple's software platforms for Macs and iOS-based devices like iPhones and iPads, 9to5Mac reported Thursday.

The site also published an image of a source page on Habrahabr.ru describing a "DoS Exploit for WebKit engine." Clicking and viewing that 9to5Mac-hosted shot of the core text exploit's publication will not affect computers and devices running OS X 10.8 or iOS 6, the site noted.

Among the affected apps was Twitter, according to one iPhone 5 ( at Amazon) owner who indicated that the app was crashing on his phone due to the exploit.

Apple was reportedly notified about this exploit "six months ago," the site reported. The company has actually fixed the bug in upcoming versions of its two major OSes, Mac OS X 10.9 and iOS 7, according to 9to5Mac, but "still has not issued a fix for the current public operating systems."

Apple did not immediately respond to a request for comment.

Until a fix is issued by Apple, 9to5Mac was pointing affected users to jailbreakers like Filippo Bigarella who are cobbling together patches, with a caveat emptor warning.

Early on Thursday, Bigarella tweeted that he had built "a fully working patch that unfortunately applies only in MobileSafari. The more general fix I came up with is not a clean solution."

Later in the day, Bigarella said he had put together a "WebCore 'dumb' patch to avoid crashes with today's malicious character sequence," with a link for downloading the patch.

Like What You're Reading?

Sign up for SecurityWatch newsletter for our top privacy and security stories delivered right to your inbox.

This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.


Thanks for signing up!

Your subscription has been confirmed. Keep an eye on your inbox!

Sign up for other newsletters

TRENDING

About Damon Poeter

Reporter

Damon Poeter

Damon Poeter got his start in journalism working for the English-language daily newspaper The Nation in Bangkok, Thailand. He covered everything from local news to sports and entertainment before settling on technology in the mid-2000s. Prior to joining PCMag, Damon worked at CRN and the Gilroy Dispatch. He has also written for the San Francisco Chronicle and Japan Times, among other newspapers and periodicals.

Read Damon's full bio

Read the latest from Damon Poeter