iOS 10.3 Fixes Exploit That Caused iPhones to Repeatedly Dial 911

iOS 10.3, released earlier this week, fixes a major vulnerability that could cause iPhones to repeatedly dial 911, reports The Wall Street Journal. In the United States, 911 is an emergency telephone number that summons police, fire, and EMS services.

The 911 security flaw surfaced in October after an 18-year-old iOS developer in Arizona discovered and published code that would cause an iPhone to dial 911 over and over again. The teenager was arrested after the 911 system in Surprise, Arizona was overwhelmed with more than 100 hang-up calls in just minutes.

iphonelinkcall
Because the code was published online, thousands of accidental 911 calls were placed across the United States, demonstrating an effective cyberattack method that could severely disrupt emergency services.

The code exploited an iPhone feature that allows users to click on a phone number in a text message or on a webpage and immediately dial that number. With the iOS 10.3 update, iPhones always require secondary confirmation before automatically calling a number using that method.

Apple says the update supersedes that capability and now requires users to always press a second confirmation before initiating a call.

Apple says it initially worked with app developers to fix the vulnerability, and this update will now prevent it from happening even on apps that hadn't already fixed the issue.

iOS 10.3, which introduces features like Find My AirPods and a new Apple Filesystem, also includes dozens of major security fixes. Another major iOS 10.3 bug fix, which could result in endless Safari pop-ups that "locked" the Safari app, was outlined earlier this week.

Top Rated Comments

cicalinarrot Avatar
61 months ago
I'd feel much more comfortable with a phone that explodes.
Well, if you have both an iPhone and a Galaxy Note 7, the iPhone can call the police for you when the Note explodes.
Score: 9 Votes (Like | Disagree)
l00pback Avatar
61 months ago
It would be really nice if these articles could offer more accurate regional details.

Enhanced 911 is currently deployed in most metropolitan areas in the United States, Canada, and Mexico as well as all of the Cayman Islands. Also, Davao City in the Philippines.
This site is for news and rumors about Apple-related products and services. It's not Wikipedia.
Score: 5 Votes (Like | Disagree)
sudo1996 Avatar
61 months ago
There was a very unfortunate case recently in the Dallas area where a child died when 911 couldn't be reached due to massive #'s of calls being made in to the system and it couldn't keep up. Hold times for 911 response were at times as much as 45 mim... Related?
There's a vulnerability in Android systems that allows unprivileged apps to spoof the cellular ID that the phone uses to identify itself on the LTE network, plus Android lets those apps make phone calls. And there's a vulnerability in LTE systems where someone can spoof a bunch of random cell IDs with fake security keys that the carrier won't check IFF they're requesting a 911 call; in fact, that phone doesn't even need to be a subscriber to that carrier. And the 911 systems have no way of telling which calls are legitimate. So it could be that.

The worst part? Even if they fix this in Android,
1. Attackers can still get away with using their own devices, and any kind of fix for this on the LTE network would require phones to be updated so they can make legit 911 calls...
2. Nobody updates their Android phones.
[doublepost=1490914369][/doublepost]
It would be really nice if these articles could offer more accurate regional details. There seems to be a huge focus on the US, maybe because the publication is based out of the US? Remember that you are reaching a global audience.

Enhanced 911 is currently deployed in most metropolitan areas in the United States, Canada, and Mexico as well as all of the Cayman Islands. Also, Davao City in the Philippines.

Knowing that this 911 bug happened elsewhere, not just the US, broadens how many people and countries that it may have impacted.
The article should really say that this bug has nothing to do with 911 and is just an exploit to force the iPhone to call any number, regardless of your service provider.
Score: 4 Votes (Like | Disagree)
thisisnotmyname Avatar
61 months ago
The article is unclear, was he arrested for publishing the vulnerability or did he exploit it himself to DoS the 911 system?
Score: 4 Votes (Like | Disagree)
6foot5foot Avatar
61 months ago
That's what I want to know too, my iPhone 6 is running fine on iOS 9.3.5, I doubt jumping to 10 will do anything but slow it down and create bugs, of course, I will be happy to be told otherwise.
I think it's a superb idea to stay with an outdated OS, leaving yourself wide open to security exploits and vulnerable... I'd advise ANYONE to do this, and whilst you're about it, go and open your front door, leave it wide open when you go to bed, and then I would post ALL your personal and financial details, website & app logins to pastebin and put them on Twitter - may as well go all out. Next, install "TeamViewer" and call any "Indian Microsoft agents" you can find by Googling that phrase, and give them your TeamViewer ID, then naively hope they're honest and won't ruin your computer.

Yes, security updates and stability patches are for mugs - be scared and cautious and stay out of date, that's the spirit, and I am sure Steve Gibson of GRC.com will advise you of the same.

I won't add the redundant "sarcasm" tag, I think you got the point.


PS: Would you like some FREE flash drives? Let me know what OS you and your friends are running, and I'll send you as many as you like :p

PS!

Please accept my gift of a free gold mercedes, shipped direct to your door for a small £100 admin fee, by clicking here:

http://adf.ly/genuinefreegoldmercedescars ('http://http://adf.ly/genuinefreegoldmercedescars')

Score: 4 Votes (Like | Disagree)
Analog Kid Avatar
61 months ago
I read about this a while ago. To be clear, this vulnerability didn't just affect 911 calls. You could force the iPhone to make a call to any number.
Nice. So he didn't have to attack critical emergency services, he just chose to do so?

"To show the seriousness" he aimed at 911. Basically, "let me hurt innocent people so you understand this could seriously hurt innocent people".

Thinking about the connection between actions and consequence is what jail is for, after all...
Score: 3 Votes (Like | Disagree)

Related Stories

iphone holiday

Best Black Friday iPhone Deals Still Available

Friday November 26, 2021 4:58 am PST by
Cellular carriers have always offered big savings on the newest iPhone models during the holidays, and Black Friday 2021 sales have now carried over into Cyber Monday as well. Right now we're tracking notable offers on the iPhone 13 and iPhone 13 Pro devices from AT&T, Verizon, and T-Mobile. For even more savings, keep an eye on older models like iPhone SE. Note: MacRumors is an affiliate...
airpods family holiday

Best Black Friday AirPods Deals Still Available

Friday November 26, 2021 4:04 am PST by
Black Friday 2021 deals are still going strong into Cyber Monday, and in this article we're tracking the best deals across Apple's AirPods lineup. Throughout the week we've been sharing the best sales for Apple devices like iPhone, Mac, and iPad, so be sure to follow us on Twitter for all of the latest Black Friday sales Note: MacRumors is an affiliate partner with some of these vendors. When...
apple mixed reality headset mockup feature purple

Kuo: Apple AR Headset Coming in Late 2022 With Mac-Level Computing Power

Thursday November 25, 2021 8:32 pm PST by
Apple's long-rumored augmented reality (AR) headset project is set to bear its first fruit late next year with the launch of the first device carrying a pair of processors to support its high-end capabilities, according to a new research report from noted analyst Ming-Chi Kuo seen by MacRumors. According to Kuo, the higher-end main processor is said to be similar to the M1 chip Apple...
apple watch cellular holiday

Best Black Friday Apple Watch Deals Still Available

Friday November 26, 2021 4:55 am PST by
The Apple Watch always makes a great gift around the holiday season, and for Black Friday 2021 we're tracking a few solid offers on numerous models of the Apple Watch. In this article, you'll find the best Black Friday sales on the new Apple Watch 7, but the best money-saving discounts will be found on older models like the Apple Watch Series 3 and SE. Note: MacRumors is an affiliate partner...
iPads black friday 20 sale feature

Best Black Friday iPad Deals Still Available

Friday November 26, 2021 4:48 am PST by
Although Black Friday sales began as early as October in 2021, the shopping holiday is now officially underway and we're highlighting the best sales for each of Apple's product lines. In this article, you'll find the best Black Friday sales on iPad Pro and iPad mini. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a purchase, we may receive a...
mac family holiday

Best Black Friday iMac and MacBook Deals Still Available

Friday November 26, 2021 4:29 am PST by
Our Black Friday 2021 coverage continues with the best deals you can find on MacBook Pro, MacBook Air, iMac, and Mac mini today. As with all Black Friday deals, we aren't sure how long any of these will last, and prices are always fluctuating, so if you see something you want, be sure to buy it soon. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and...
General black friday 20 sale feature

Huge List of Black Friday Deals on iPhone and Mac Cases, Cables, Accessories and Software

Friday November 26, 2021 5:09 am PST by
Black Friday is in full swing today, and in this article we're highlighting some of the best deals that you can find online among popular third-party accessory makers like Twelve South, Nomad, Satechi, and many more. Visit our Black Friday Roundup for a deeper dive into the best sales going on today. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and...
apple black friday shopping event 2021

Apple's Black Friday Promotion Now Underway in the U.S. and More Countries

Friday November 26, 2021 12:07 am PST by
Apple's annual four-day Black Friday through Cyber Monday shopping event is now underway in the United States and select other countries, with customers able to receive a free Apple gift card with the purchase of select products through November 29. Participating countries include the United States, Canada, Australia, New Zealand, the UK, Ireland, France, Spain, Portugal, Italy, Germany,...