Apple missed a serious vulnerability that could have affected some of their customers

Nov 8, 2011 16:07 GMT  ·  By

A security researcher called Charlie Miller discovered a serious vulnerability in iOS that would allow a remote attacker to run an unsigned code from a remote server.

Threat Post reported that in order to prove his findings he submitted an application to the iTunes App Store and once it was approved he could use it prove his findings.

The app was designed to connect to a web server during the installation process and check for an exploit file that was carefully placed. The demo revealed that cybercriminals can profit from this weakness and run a malicious code on any device that runs on iOS.

Even though the exploit was only present during the demo, other users also downloaded the app, fact which made Apple unhappy, kicking him off the developer program.

The video demo is available here.