If you're using Skype for iOS version 3.0.1 or older, you might want to think twice before opening messages from people you don't know. According to a security expert, a cross-site scripting (XSS) vulnerability exists in the Chat section of Skype for iOS on both the iPhone and iPod touch.
Apparently, Skype fails to properly encode the "full name" of the sender of an incoming chat message, allowing the sender to add malicious JavaScript code that can be executed as the message is opened...