Malicious Link Texted to Mac and iOS Devices Can Cause Freezes and Resprings [Updated] - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Malicious Link Texted to Mac and iOS Devices Can Cause Freezes and Resprings [Updated]

by

A link that exploits a bug in iOS and Mac devices was shared on Twitter this afternoon, and if you receive this link through the Messages app, your iPhone or iPad can freeze up or respring, and the Messages app can become unusable.

The link, which goes to a Github page, breaks the Messages app and causes problems on both iOS devices and Macs. Simply receiving the link results in issues, likely due to the Messages feature that lets you preview web links. We tested the bad link and while we saw few resprings, it did reliably cause the Messages app to freeze entirely.

githubtextbug
The only solution appears to be to quit out of the Messages app and then delete the entire offending conversation to restore full functionality.

These kinds of Message-based bugs have surfaced several times in the past, with text strings, videos, and more crashing the Messages app in the past. Such bugs are not serious, but they can be highly irritating when abused as a prank.

It's best not to send the link to friends, because it can cause the sending device to freeze up and crash as well. If your device is affected, quit the Messages app on Mac or iOS, open it back up, and immediately delete the entire message thread.

On Mac, you'll need to swipe right on the trackpad or right click on to the person's name to delete the conversation, while on iOS, you'll need to swipe to the right on a person's name to bring up the delete option.

websiterestrictions
Blocking the domain using Parental Restrictions may prevent the link from affecting your iOS devices. You can turn on Restrictions on iPhone or iPad by going to Settings --> General --> Restrictions --> Websites --> Limit Adult Content and adding "GitHub.io" to the "Never Allow" list.

Update: Apple appears to have addressed the bug in iOS 11.2.5 beta 6, and Github has removed the offending webpage.

Top Rated Comments

Porco Avatar
111 months ago
IMHO, Apple should offer an option to specifically turn off web link previews, regardless of this bug.
Score: 23 Votes (Like | Disagree)
Naraxus Avatar
110 months ago
Does anyone remember when stuff like this happened to Microsoft and NOT Apple? My how times have changed.
Score: 17 Votes (Like | Disagree)
Princess Cake Avatar
110 months ago
M$ still sucks, and Apple is still better.
Remember what Steve said "We have to let go of this notion that for Apple to win Microsoft has to lose. In order for Apple to win Apple needs to do a really good job."
Score: 15 Votes (Like | Disagree)
Princess Cake Avatar
111 months ago
O̖̟̝̦h ̱l͉̰͓ooḳ,̩̗̱ ̩͓̘͔t͕͚h̬̰̗̘̣̙͔e̝̮̯̟͍ ̗̖͔̣k̗̩̩̳͓̜͔i͚d͎̯̭s̭̙̣ ̟̫̳a̞ṛ̩̮̪̣͚e͚̰̺͔̭ ̟̜̥̖͇͓̝u̱̠s̬̯̥̳̲̠in̪̲g̜̣̝̦ ͓t̬̞hḙ̳̣ ͇͙̗͈̺̮͓g̠̱̣̭̦͕͓ḽḭ̞̘t̩c̤͎h̺̬͕̜̘̲y̞͉̘ t͔̥̰e͙̭͇̼̱̹x̙̠t̜͇̝̹ͅͅ ͔̞̠̱ge͚n̗e͍̦̝̺r̦͓a͇̳̣t͖̦̱͔̤̙o͓̭̗̹̤̜̼r͔͙̗̬̞̼͚:rolleyes:
Score: 14 Votes (Like | Disagree)
shamino Avatar
110 months ago
So does anyone have a clue what this page is actually doing? I tried loading it in Firefox and the browser got really slow (displaying assorted cruft at the bottom of the browser window) until I closed the tab.

Update

After viewing the page's source code, it's just ugly nonsense exploiting a bug in the browser.

The page's header has a meta tag (og.title (http://ogp.me/)) where the content is several MB of text, consisting mostly of Unicode cascading accent marks. Following by a "mailto" URL containing similar junk. The content causes most software (capable of displaying Unicode, of course) to slow down a lot.

Pretty juvenile. But iOS's Mobile Safari and Messages shouldn't crash in the face of this. This may indicate a more serious bug somewhere in Apple's Unicode rendering engine.

IMO, although it probably violates the standard, I think software should put a limit on the number of cascading accents one may attach to a single character. If there were a limit of 100 (for example), it would probably never interfere with legitimate text and text designed to abuse the feature would simply fail to render. The only people offended would be those trying to write browser-crashing text and a few uber-pedantic Unicode geeks.
Score: 10 Votes (Like | Disagree)
111 months ago
Apple is lost. This is the effective power bug all over again.
Score: 10 Votes (Like | Disagree)

Popular Stories

iCloud iPhone 17 Pro

iPhone Users Who Pay for iCloud Storage Get Two New Perks on iOS 27

Thursday July 2, 2026 6:10 am PDT by
If you pay for certain iCloud+ storage plans beyond the 5GB that Apple offers for free, you will receive two more perks on iOS 27 at no additional cost. A summary of the two new iCloud+ perks on iOS 27:Increased daily usage limits for some new Apple Intelligence features, including image generation in the revamped Image Playground app. HomeKit Secure Video cameras receive generated video...
iPhone 4 on Black Feature

Apple Facing One of Its Worst Leaks Since the iPhone 4

Thursday July 2, 2026 9:53 am PDT by
Apple supplier Tata Electronics recently suffered a cyberattack that resulted in thousands of confidential files being published on the dark web, and this reportedly included some photos and documents related to the upcoming iPhone 18 Pro. We have elected not to share any of the leaked photos in this story due to the illegal nature in which they were obtained, but they can easily be found...
Apple Event Logo

Apple Just Released a New Product

Thursday July 2, 2026 8:04 am PDT by
Apple's first product release of summer 2026 occurred this week, but do not get too excited, as it is merely the Beats Solo Buds in a new color. Beats Solo Buds are now offered in orange through Best Buy in the U.S., with availability set to expand to 7-Eleven stores in Japan on July 4. Apple already offered orange Solo Buds in India for free with the purchase of an iPhone 15 or iPhone 15 ...