Skype On iOS Has Vulnerability That Lets Others Steal Address Book [News]

For avid Skype users on Apple devices, you need to be careful. There is a vulnerability in the current iOS version of Skype that allows users to get access to your address book. Obviously, this is not the most earth shattering hack, since there isn’t too much a hacker can do with just an address book. Still, I don’t think you or your contacts would want that information in the hands of hackers.

Skype is aware of the exploit, but they don’t seem too concerned about getting it fixed right away. They said it will be addressed in the next scheduled update, so they don’t seem to consider this an emergency.

Basically this a JavaScript exploit and according to security expert Phil Purviance:

Skype uses a locally stored HTML file to display chat messages from other Skype users, but it fails to properly encode the incoming user’s ‘Full Name,’ allowing an attacker to craft malicious JavaScript code that runs when the victim views the message.

So basically, if you open a chat with a malicious person, they can get access to your friends list and do whatever they like with the information, and as I said before, this will not make your friends too happy. Until the update comes out just be careful about what chats you receive and read on your iPhone.

Source: MacWorld via Superevr


MakeUseOf Recommends

Dave LeClair

Dave LeClair (Twitter), has been writing reviews of iOS games for years, and is also a big time gamer on Xbox [websterrjh]. You can watch Dave play DOTA 2 on his Twitch stream @ twitch.tv/sideox.

The comments were closed because the article is more than 180 days old.

If you have any questions related to stuff mentioned in the article or need help with any computer issue, just ask it on MakeUseOf Answers.

Hide 4 Comments

  • Jshm2 September 21, 2011
    0 likes

    “So basically, if you open a chat with a malicious person, they can get access to your friends list and do whatever they like with the information, and as I said before, this will not make your friends too happy. Until the update comes out just be careful about what chats you receive and read on your iPhone.”

    Everyone knows iphone users have no friends so this doesn’t bother too many of them…

    | Like
  • Anonymous September 22, 2011
    0 likes

    but… but … but…. isn’t  apple’s  magical OS supposed to sprinkle pixie dust on everything on it and make it hack/virus/malware/spyware proof?

    | Like
    • Tina September 29, 2011
      0 likes

      If wishes were horses…

      | Like