Blog post main image
Code Blue Communications > Blog > chaIOS “Text Bomb” Threat

chaIOS “Text Bomb” Threat

23rd January 2018

What is chaIOS?

chaIOS is a bug that can cause iOS devices (iPhones an iPads) and Mac OS to crash. In some cases, the phone/device/Mac will need restarting to resume normal activity. The bug is caused by a message received on iMessage, this bug will cause a loop on the device/phone/Mac which will slow down the device and eventually grind to halt and crash.

 

 

How does the bug work?

chaIOS works by sending a webpage with specific JavaScript that will attempt to send a message. This bug is reminiscent of ‘Effective Power’. Effective power was a bug that crashed iMessage and cannot be opened without crashing. The link that sent across to another device to crash it is identified below.

http://iabem97.github.io/chaiOS

 

Who does the bug affect?

The bug affects the following;

·       Mac OS: High Sierra

·       iOS 10 to iOS 10.3.3

·       iOS 11 to 11.2.1

 

What can be done to remedy this?

Apple will look to release an update in the future will that will remedy this message from crashing iOS and Mac OS devices. The following can be done to mitigate the effect until Apple releases a security update.

Block the domain of the site – Go to Safari settings> General> Restrictions > Enable Restrictions > Websites > Limit Adult Content > Never Allow > Github.io

Reset you iPhone to factory settings – The last resort is the issue is persistent or the phone/device becomes unusable

Wait for the patch from Apple – Apple is aware of the issue and will be sending out a security patch to fix chaIOS.

X
Call Back Request