Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

An iMessage 'text bomb' is floating around that can freeze your iPhone (or Mac)
iMore ^ | January 17, 2018 | By TORY FOULK

Posted on 01/18/2018 2:56:51 PM PST by Swordmaker

A bug publicly released by a developer can freeze — and possibly crash — your device if you open it in Messages.

According to an article by Nicole Nguyen at Buzzfeed, yesterday afternoon software developer Abraham Masri publicly posted the bug — a security vulnerability called "chaiOS" that he found while attempting to break the operating system via "fuzzing" — to Github. Fuzzing is essentially a way of testing for vulnerabilities that involves putting way too much data into a system in order to crash it.

👋 Effective Power is back, baby!

chaiOS bug:
Text the link below, it will freeze the recipient's device, and possibly restart it. https://t.co/Ln93XN51Kq

⚠️ Do not use it for bad stuff.
----
thanks to @aaronp613 @garnerlogan65 @lepidusdev @brensalsa for testing!— Abraham Masri (@cheesecakeufo) January 16, 2018

Here's how the bug works according to Buzzfeed's piece:

When someone texts you a link to a website through Messages in iOS, the app generates a preview of the link. Apple's software guidelines allow developers to insert a small amount of characters into their website's HTML to customize the image and title of that link preview. Instead of a small amount of characters, Masri inputted hundreds of thousands of characters into a webpage's metadata, much more than the operating system expects, which Masri suspects is why Messages crashes. He then hosted the bug's code on Github, which made it available for other people to use.

What really, really sucks? Once someone sends you the link to the page with tons of extra characters in its metadata through Messages, it will crash your phone, even if you don't click it or interact with it in any way. This basically means that all someone needs to freeze up your device for a few minutes (if not break it completely) is your phone number. Masri says the bug can also affect Macs.

Twitter user @aaronp613, one of the testers of the bug, spoke with Buzzfeed about what happens after the link is sent:

The device will freeze for a few minutes. Then, most of the time, it resprings.

Aaron then told Buzzfeed that once your phone reboots, the Messages app still won't load and will continue to crash. He also reported that the bug affects iOS versions 10.0 through 11.2.5 beta 5, though he has yet to tested it on iOS 11.2.5 beta 6 — the latest beta — which was released this earlier today.

The Github page hosting the code for the chaiOS vulnerability has been taken down and Masri's account has been suspended since he posted the link on Twitter. However, that doesn't mean that it's gone for good — because Masri's Github was open to the public, it's likely that someone else has already re-copied it and posted it elsewhere.

Masri stated in his chat with Buzzfeed that he has reported the bug to Apple, and that releasing it was to get Apple's attention as the company reportedly routinely ignores his reports:

My intention is not to do bad things. My main purpose was to reach out to Apple and say, 'Hey you've been ignoring my bug reports.' I always report the bug before releasing something.

And it seems it worked — Apple confirmed to Buzzfeed that a fix for the bug is currently in the works, and will be released in an update next week. There is no word about whether or not Apple has responded to Masri directly, however.

So what can I do?

Basically, be vigilant. If you see that you've received a link you don't recognize that you think may be running the chaiOS bug, delete it immediately (if you're able). However, that may not be possible, because in some cases Messages will crash before you're even able to open it. If you're not able to open the messages app whatsoever due to the bug, you may consider resetting your phone to its factory settings by doing a full restore. However this will delete your photos and anything else saved to your device.

Outside of that, it's always a good idea to make sure your phone is running the latest version of iOS — Apple routinely fixes vulnerabilities in updates, and this is no different. Definitely update to the newest iOS as soon as you're able.

For more information regarding the chaiOS bug, you can check out Buzzfeed's article.



TOPICS: Business/Economy; Computers/Internet
KEYWORDS: applepinglist; ios; macos; messagingbug

1 posted on 01/18/2018 2:56:52 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; 5thGenTexan; AbolishCSEU; Abundy; Action-America; acoulterfan; AFreeBird; ...
A bug in iMessage can cause it to crash when a message with a link to an image with hundreds of thousands of characters in the meta data. This can also cause the iOS device or even a Mac to crash and restart. If you receive an iMessage with an unexpected link, don't open it. Apple is preparing a fix for this bug. — PING!


Apple iMessage Bug Can Cause Crash
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

2 posted on 01/18/2018 3:00:36 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

That damn Micros... oh.


3 posted on 01/18/2018 3:01:34 PM PST by Ingtar
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
So what can I do?

If you know someone sending these assaults to anyone else, be sure that he has a little "accident" that will leave him unable to use those offending fingers to type out any more "bugs"!

4 posted on 01/18/2018 3:28:13 PM PST by JimRed ( TERM LIMITS, NOW! Build the Wall Faster! TRUTH is the new HATE SPEECH.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Definitely update to the newest iOS as soon as you're able.

Mine has required me to update several times in the past couple of months. Hope that's what they were covering.

5 posted on 01/18/2018 3:30:30 PM PST by JimRed ( TERM LIMITS, NOW! Build the Wall Faster! TRUTH is the new HATE SPEECH.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: JimRed

Do you suggest breaking fingers or just cutting them off?


6 posted on 01/18/2018 3:32:27 PM PST by Irish Eyes
[ Post Reply | Private Reply | To 4 | View Replies]

To: JimRed

Because only telemarketers who spoofing phone numbers, not hackers, right?

Spoofing IS hacking.


7 posted on 01/18/2018 4:06:14 PM PST by a fool in paradise (Did Barack Obama denounce Communism and dictatorships when he visited Cuba as a puppet of the State?)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Irish Eyes; JimRed
Do you suggest breaking fingers or just cutting them off?

Break them first, then cut them off. 😄

8 posted on 01/18/2018 4:12:15 PM PST by Mark17 (Genesis chapter 1 verse 1. In the beginning GOD....And the rest, as they say, is HIS-story)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker
If you're not able to open the messages app whatsoever due to the bug, you may consider resetting your phone to its factory settings by doing a full restore. However this will delete your photos and anything else saved to your device.

I always tell people to back up their devices. Frequently. I've had to help people by recovering their precious photos and important data, and they hadn't backed up their data. If it's important, it should be backed up to a safe place.

9 posted on 01/18/2018 4:12:55 PM PST by roadcat
[ Post Reply | Private Reply | To 1 | View Replies]

To: JimRed
Mine has required me to update several times in the past couple of months. Hope that's what they were covering.

No, the fix for this newly discovered bug is due next week. In the meantime, don't open a link in an iMessage from someone you don't recognize or from someone who is prone to nasty practical jokes.

10 posted on 01/18/2018 4:26:18 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Irish Eyes
Do you suggest breaking fingers or just cutting them off?

Drawing and quartering is well thought of in some areas. . . personally I prefer to run them through a meat grinder.

11 posted on 01/18/2018 4:27:35 PM PST by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you racist, bigot!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker

I see you have similar thoughts as I regarding malicious hackers. Also telemarketers and other spammers, for me. You?


12 posted on 01/18/2018 4:32:05 PM PST by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker

;)


13 posted on 01/18/2018 4:33:31 PM PST by Irish Eyes
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker
"In the meantime, don't open a link in an iMessage from someone you don't recognize or from someone who is prone to nasty practical jokes."

Or maybe just keep your phone turned off for the next week.

From the article:

14 posted on 01/18/2018 4:38:29 PM PST by Garth Tater (What's mine is mine.)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Swordmaker

The guy needs about 99 years in prison to consider his actions.

Then he should be punished.


15 posted on 01/18/2018 5:43:25 PM PST by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson