IntoMobile

Breaking news, information, and analysis on the latest mobile phones and mobile technology

Open NavigationOpen Search
  • Home
  • Platforms
    • iOS / iPhone OS
    • Android
    • Windows Phone
    • BlackBerry OS
  • Hardware
    • New Hardware
    • Tablets
    • Reviews
    • Rumors
  • Carriers
    • AT&T
    • Sprint
    • T-Mobile
    • Verizon
  • Manufacturers
    • Apple
    • Samsung
    • HTC
    • LG
    • Motorola
  • Best VPNs
  • Best AI Tools

WebOS hacked via text messages

April 19, 2010 by Marin Perez - Leave a Comment

Share on Twitter Share on Facebook ( 0 shares )

A researcher has found a way to hack into webOS devices merely using text messaging but the vulnerability only affects an older version of the firmware, which should limit the impact.

Intrepidus Group, a mobile security group, said webOS was “riddled with some pretty dangerous bugs” due to the fact that many of its applications are written with HTML, JavaScript and other standard web technologies. One of the most disturbing security holes is the issue with how it handles text messages.

“The webOS SMS client wasn’t performing input/output validation on any SMS messages sent to the handset,” the security company said. “This leads to a rudimentary HTML injection bug. Coupled with the fact that HTML injection leads directly to injecting code into a webOS application, the attacks made possible were quite dangerous (especially considering they could be delivered over a SMS message).”

The “good” news is that this vulnerability is only applicable for webOS 1.3.5, and many U.S. users should already be on 1.4. Still, the mobile security firm was very harsh on Palm:

We understand, of course, that there are a number of competing interests that go into the development of a new mobile platform … However, we feel that Palm put almost no thought into security during their development of webOS. All of the low hanging fruit discovered should have been identified in the most basic of threat models, which should have been performed during the very early development stages of webOS, way before any code was written.

Wow. I’m not a security nut by any measures but a widespread attack on mobile phones could set this industry back a long time, so you need to get your game together Palm! At least if the company gets acquired, it will have more resources to focus on security. Check out the video below to see how easy it is to crack webOS.

[Via ZDNet]

Share on Twitter Share on Facebook ( 0 shares )

Back to top ▴

Back to top ▴

Follow IntoMobile

38k
36k
4k
13k
12k

Most Recent Posts

  • iQOO Neo 11 Ultra is coming, and the specs are already turning heads
  • iQOO Buds first look: a new TWS is coming on August 20th
  • Pova AI Buds Pro launched in India with meeting summaries and 48dB ANC
  • Honor Magic 9 is ditching glass for full metal, and that’s a bold move
  • Huawei’s wide non-foldable phone could arrive sooner than anyone expected

Get Updates Via E-Mail

  • This field is for validation purposes and should be left unchanged.

About IntoMobile

  • About IntoMobile
  • Contact IntoMobile
  • Send us News Tips
  • Privacy Policy

Social Links

  • IntoMobile on Facebook
  • IntoMobile on Twitter
  • IntoMobile on Google+
  • IntoMobile on YouTube

Copyright © 2006-2021 IntoMobile. All rights reserved.