TechNeate.com iPhoneate.com QueComico.com MiamiGlobalRadio.com

Critical vulnerability persists in Apple's iTunes and App Store

by Lisander González / July 30, 2015 3:46 PM EDT

Apple users have been affected by a recently discovered vulnerability that is critical to the functions of the Apple App Store and iTunes.

Screenshot_2

The information was published by Apple's security team on June 9, 2015. This information is so serious due to several factors that jeopardize the security of all users of these services. If hackers were to exploit this vulnerability, they could hijack the sessions of all affected users or prevent them from using the service correctly by redirecting them to external links, among other sensitive actions that would be catastrophic for everyone, including the company itself, as the level of distrust continues to grow. Apple promised to resolve the problem within a month, but what guarantees can they give users that this problem will not happen again?

Information was released to the public regarding how the aforementioned vulnerability worked. This vulnerability, if exploited by a remote hacker, would involve the execution of malicious script code . This would cause the attacker, upon purchasing a product from any of the affected services, to have the malicious code retrieved by the service store, resulting in the execution of said malicious code within the Apple App Store application. According to the investigator in this case, he stated the following:

The invoice is present for both parties (buyer and seller), which demonstrates a significant risk for buyers, sellers, or Apple website managers/developers. The impact of the problem also includes the risk that a buyer can be the seller by using the same name to compromise the integrity of online service warehouses.

Critical persistent vulnerability in Apple App Store and iTunes

The researcher was referring to the case of acquiring products from online stores. Furthermore, the information was demonstrated through a test based on this concept, which outlines all the steps to exploit this vulnerability. It's unclear whether disclosing how the vulnerability works is a good or bad thing, since a similar error could occur in the not-too-distant future, and this information could be misused.