Skip to main content

Security researcher shares web code snippet that causes iPhones and iPads to kernel panic and reboot

Links that cause iPhones and iPads to crash or reboot have become a bit of a trend in recent years. The latest was released by security researcher @pwnsdx over Twitter. What’s interesting about this one in particular is it relies on a simple snippet of HTML and CSS and causes a full device kernel panic, beyond just a simple Springboard crash.

The bug affects any iOS device that can interpret the background-filter effect, something which was first introduced in iOS 7. Essentially, the few lines of CSS apply a computed blur effect to every div element on the page. The accompanying HTML includes a lot of div elements.

The computationally-expensive drawing overloads the WebKit renderer and the system cannot recover other than to kernel panic, crash to the Apple logo, and reboot.

You can see the source code of the bug here; it’s only a few lines of HTML and CSS. You can open the ‘safari-ripper.html’ link on that page if you want to try it out yourself — but the usual disclaimers and warnings apply. 9to5Mac has confirmed it does work on iOS 11 and iOS 12, so you don’t have to. It can also cause some desktop web browsers to freeze up.

Unlike similar text message crashing cases that can spread like chain-mail over iMessage notifications, this requires the user to visit a web page that contains the problematic code. At worst, this code could be incorporated into a HTML email message that causes the device to crash when the message is opened.

This means there is a relatively low chance of real-world damage. That being said, CSS and JavaScript should never be able to take down a system like this. Apple and the WebKit groups will no doubt roll out a fix in the coming weeks that will make its way into a future iOS update.

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Benjamin Mayo Benjamin Mayo

Benjamin develops iOS apps professionally and covers Apple news and rumors for 9to5Mac. Listen to Benjamin, every week, on the Happy Hour podcast. Check out his personal blog. Message Benjamin over email or Twitter.


Manage push notifications

notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications
notification icon
We would like to show you notifications for the latest news and updates.
notification icon
You are subscribed to notifications