iPhone Flaw Allows SMS Spoofing, Says Hacker

17.08.2012
A hacker known for jailbreaking Apple devices claims that the iPhone is vulnerable to text message spoofing, even in the latest beta of iOS 6.

According to , this issue could allow scammers to send people to phishing Websites under the guise of a financial institution, or allow criminals to plant spoofed messages as false evidence on other peoples' phones. It also opens up other types of manipulation where the recipient thinks a message is coming from a trusted source.

As pod2g explains, all text messages are converted to a format called Protocol Description Unit, which spells out the many types of information an SMS needs to reach its destination. One of these information types is the UDH (User Data Header) indicator, which allows the user to change the reply address of the message.

The problem with the iPhone is that when the sender specifies a reply-to number this way, the recipient doesn't see the original phone number in the text message. That means there's no way to know whether a text message has been spoofed or not.

"In a good implementation of this feature, the receiver would see the original phone number and the reply-to one," . "On iPhone, when you see the message, it seems to come from the reply-to number, and you loose track of the origin."

Other Handsets No Stranger to Spoofing