SMS Attack on BlackBerry Smartphones – Update Device Software
According to an advisory published by Research In Motion (RIM), BlackBerry mobile devices are open to attack due to a certificate notification flaw in the smartphone’s software. The problem lies in the BlackBerry Browser dialog box that alerts users if the URL they have clicked on does not match the domain they are being sent to.
Using this security flaw, a malicious user could create a web site that includes a certificate that is purposely altered using null (hidden) characters in the certificate’s Common Name (CN) field or otherwise manipulated to deceive a BlackBerry device user into believing they have connected to a trusted web site. […]
