JavaScript-Based Safari Ransomware Exploit Patched in iOS 10.3

iOS 10.3, released to the public this morning, fixes a bug that allowed scammers to attempt to extort money from iOS users through a JavaScript pop-up in Safari.

As explained by mobile security firm Lookout (via Ars Technica), the scammers targeted iOS users viewing pornographic material and abused JavaScript pop-ups to create an endless pop-up loop that essentially locked the browser if the user didn't know how to bypass it.


Using "scareware" messages and posing as law enforcement, the scammers used the pop-ups to extort money in the form of iTunes gift cards from the victim, promising to unlock the browser for a sum of money.

The scammers abused the handling of pop-ups in Mobile Safari in such a way that a person would be "locked" out from using Safari unless they paid a fee -- or knew they could simply clear Safari's cache (see next section). The attack was contained within the app sandbox of the Safari browser; no exploit code was used in this campaign, unlike an advanced attack like Pegasus that breaks out of the app sandbox to install malware on the device.

The scammers registered domains and launched the attack from the domains they owned, such as police-pay[.]com, which the attackers apparently named with the intent of scaring users looking for certain types of material on the Internet into paying money.

The endless pop-up issue could be fixed by clearing the Safari cache, but many users likely did not know they didn't need to shell out money to regain access to their browsers.

Pop-up scams are no longer possible with iOS 10.3, as Apple has changed the way pop-up dialogs work. Pop-ups are now per-tab and no longer take over the entire Safari app.

Top Rated Comments

(View all)
Avatar
44 months ago
Great news. These pop-up loops are the worst thing and they don't belong in 2017. Now Apple needs to prevent Safari ads from automatically taking you to the App Store for some crappy IAP fest game.
Score: 48 Votes (Like | Disagree)
Avatar
44 months ago
Finally, I can search for porn again.
Score: 19 Votes (Like | Disagree)
Avatar
44 months ago

I think it's all on apple to stop these scams and also refund anyone duped by them, because they've allowed a third party to effectively break the device and allow the scam to work.

"Allowed" how? Did they give the scammers instructions on how to "break" the device?

Good luck suing the makers of door locks or plate glass for "allowing" a burglar to pick the lock or break a window. Good luck suing the police for "allowing" the break-in. Good luck suing the telephone company for "allowing" a scammer to place a call, or the city for "allowing" a scammer to ring your doorbell. Failing to provide 100% safety is not the same as "allowing" a crime to occur.

The creators of these browser scams find weaknesses in the software. The developers of browsers plug the weaknesses. That's the same cat-and-mouse game you find anywhere there's crime.

Browsers are a particularly good target because, among other things, browsers are expected to correctly display web pages, regardless of who created that web page. Open Internet, and all that. You want a guarantee of 100% safety? Don't use the Internet.

I love the diversity around here. Some people complain that Apple's software allowed a scam to occur. Apple (presumably) attends to their needs by issuing software updates to combat the scams. Others are all up in arms, "How dare Apple force these updates upon us!"
Score: 8 Votes (Like | Disagree)
Avatar
44 months ago

And I hope Apple can STOP the automatic update downloads.
Sometimes I run out of storage and Apple still sends the signal to download the iOS update.

as a developers, i hope they will continue with the automatic update.

the moment user have a choice in that, people will never update their OS and it just goes downhill from there.
Score: 7 Votes (Like | Disagree)
Avatar
44 months ago
And I hope Apple can STOP the automatic update downloads.
Sometimes I run out of storage and Apple still sends the signal to download the iOS update.
Score: 4 Votes (Like | Disagree)
Avatar
44 months ago

There is a switch to stop app updates, but that doesn't include iOS itself? Unfortunate that Apple hasn't provided user control over that yet, but they do provide a way of deleting the downloaded update now.

https://www.igeeksblog.com/how-to-remove-software-update-download-from-iphone-ipad/

Except they force the download on you again as soon as you are connected to a Wifi Network, not only wasting space on your phone but wasting your download quotas on wifi - something extremely annoying and expensive if you live in a rural area, or are using hotel wifi. How about just having an opt-out option, or at least not immediately downloading it again if it is deleted.
Score: 4 Votes (Like | Disagree)

Top Stories

Apple Confirms This Year's iPhone 12 Models Will Be a Little Bit Late

Thursday July 30, 2020 2:34 pm PDT by
During today's earnings call covering the third fiscal quarter of 2020 (second calendar quarter) Apple CFO Luca Maestri confirmed that Apple is expecting to release this year's iPhones later than usual. Maestri said that Apple last year started selling iPhones in late September, but this year, Apple projects supply will be "available a few weeks later." Multiple rumors have suggested that ...

Apple-Acquired Dark Sky Officially Shuts Down Android App

Saturday August 1, 2020 3:43 pm PDT by
Apple in March purchased weather app Dark Sky, and at that time, Dark Sky's developers said that the app's Android version would be discontinued on July 1, 2020. However, instead of shuttering the app on that date, the app's developers announced that the discontinuation would be delayed for another month. Now that it's August, Android users are no longer able to access the app, and...

Apple Watch Series 6 to Feature Blood Oxygen Monitoring Sensor

Friday July 31, 2020 1:56 am PDT by
The Apple Watch Series 6 will add blood oxygen monitoring to its features list when it's launched later this year, according to a new report from DigiTimes. Apple Watch 6 will feature biosensors that can monitor sleeping conditions, detect blood oxygen and measure pulse rates, heartbeats and atrial fibrillation, and will also incorporate MEMS-based accelerometer and gyroscope, all allowing the ...

Just How Small Will the 5.4-Inch iPhone 12 Screen Be? Try It Out for Yourself

Tuesday July 28, 2020 12:57 pm PDT by
As rumors of the iPhone 12 have continued to build over the past few months, the one model that has the most excitement around it is the smallest 5.4" model. The iPhone 12 is believed to be coming in 5.4", 6.7", and 6.1" sizes. Dummy models have shown how much smaller the 5.4" is compared to the rest of the iPhone lineup. The upcoming 5.4" iPhone falls in-between the size of the original...

Top Stories: Try the 5.4-Inch iPhone 12 Display Size, Blockbuster Earnings, Tim Cook at Antitrust Hearing

Saturday August 1, 2020 6:00 am PDT by
Another busy week of Apple news and rumors has wrapped up, with a lot of focus on Tim Cook's appearance at a Congressional antitrust hearing and a blockbuster earnings report. Subscribe to the MacRumors YouTube channel for more videos. We continued to hear rumors about the upcoming iPhone 12 lineup, including a rare admission from Apple that the lineup will launch "a few weeks later" than...

Emails Reveal Why Steve Jobs and Phil Schiller Blocked In-App Purchase of Kindle Books

Friday July 31, 2020 6:25 am PDT by
Internal Apple emails, made public by the House Judiciary Committee's antitrust inquiry, have revealed information about why Apple blocked in-app purchases of Kindle books on iOS devices, reports The Verge. Two sets of emails between Steve Jobs, Phil Schiller, Eddy Cue, and various other senior Apple executives, disclose the exact thinking behind how Apple approached Kindle on iOS. The...

Battery Likely for Upcoming Apple Watch Series 6 Filed in Certification Listings

Saturday August 1, 2020 5:46 am PDT by
A battery likely for the upcoming Apple Watch Series 6 has been filed at the Korea Testing and Research Institute and discovered by a Twitter user @yabhishekhd. Certification for a 1.17Wh battery with a capacity of 303.8mAh was issued on June 23 by the KTR, a Korean regulatory body that approves and tests new hardware ahead of public sale. The battery seems to be destined for a future...

Apple Marks Return of NHL With New 'Hockey Tape' Ad Shot on iPhone 11 Pro

Saturday August 1, 2020 2:33 am PDT by
Apple today marked the return of NHL hockey with a new "Shot on iPhone" ad on its YouTube channel in Canada. Titled "Hockey Tape," the 30-second video features Vegas Golden Knights players Marc-André Fleury and Mark Stone having some on-ice fun with the iPhone 11 Pro, which they attach to the boards, a hockey stick, and a skate with hockey tape. "See the game like never before with Ultra ...

Apple Launches New Gift Card for 'Everything Apple'

Friday July 31, 2020 3:45 am PDT by
Apple has introduced a new single gift card in the U.S. for all things Apple. First spotted by iCulture, the card can be used at the App Store and other online services, but you can also use it to buy products and accessories in the Apple Store. Previously, there were two separate Apple gift cards available: iTunes cards, which can be used for App Store, iTunes Store, and iCloud storage...

Leaker Jon Prosser Claims iPhone 12 and New iPads Will Launch in October

Wednesday July 29, 2020 4:15 pm PDT by
Leaker Jon Prosser, who has a somewhat mixed track record when it comes to predicting Apple's plans, today said that new iPhone 12 models and new iPads will launch in October. Multiple rumors have suggested that some or all of the iPhone 12 models coming this year will see a later than normal launch. Apple typically unveils and releases new iPhones in the month of September, but problems...