Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've never had this kind of experience for the past 14 years on iOS. How could a website get access to call numbers without interaction?


I have encountered websites attempting to call a number, but not repeatedly prior to that. I assume it’s through JavaScript, of course.

It pops up an interface on the lower side of the screen asking “do you want to dial this number?” or something like that. This seems to be the relevant doc: https://developer.apple.com/library/archive/featuredarticles...


It's spamming the modal asking if you want to call x phone number, probably.


The corruption of the interface was the most disturbing thing. It was showing the left-hand slide home screen menu offset, overlapping with other elements, without any ability to interact with it. It must be some sort of memory corruption vulnerability, I assume. Apple did an update a week or two later which addressed some sort of zero day… So clearly I was wondering exactly how hacked my phone might have been. I was able to reboot and it has seems OK, but who knows.


Apple addresses zero days and security related bugs every single update, I wouldn't get paranoid about a visual glitch on its own honestly.


It prevented me from launching, switching or killing any apps or rebooting the phone. The phone was entirely unusable until I figured out how to reboot. That's more than visual. My impression is that is was memory only, but it was extremely suspicious. It’s quite possible that data was exfiltrated.


Simply locking up Springboard with a DoS doesn't necessarily mean your were breached on the device. It's more likely that nothing came of it, exfiltrating data would involve breaching a lot of sandboxing and we'd be seeing a lot more chatter about that honestly.


Sure, there’s been no evidence of anything wrong since then, either with my phone or related accounts. Apple did fix a couple 0 days with more serious implications shortly after this, but it’s not as if I or a random search result website would be worth someone using a 0 day.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: