Yesterday we reported on an SMS exploit that could cause iPhone users to send text messages to numbers they haven't selected, and now Apple has responded by warning users to be cautious when using SMS — and pointing to iMessage as a more secure alternative. "Apple takes security very seriously," a company spokesperson told us. "When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks."
As highlighted by iOS hacker pod2g, the vulnerability consists of changing the "reply-to" field in the header of an SMS message. In the iOS Messages app, users see the number specified in the reply-to field as the originator of the message, even if it has come from a different source. Any replies...
Continue reading…