Security flaw in Apple iPhones gives hackers control
By Stewart Mitchell and Reuters
Posted on 4 Aug 2010 at 08:23
The same flaw used to jailbreak Apple's iPhone and iPad could allow hackers to enslave the mobile devices, according to security firms.
The PDF flaw affects Apple's iOS, which also runs the iPod Touch, and could allow hackers to take complete control of a vulnerable device.
“Two vulnerabilities have been identified in Apple iOS for iPhone, iPad and iPod, which could be exploited by remote attackers to take complete control of a vulnerable device,” said McAfee's David Marcus on the company's blog.
“The first issue is caused by a memory corruption error when processing Compact Font Format (CFF) data within a PDF document, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page using Mobile Safari," he said.
“The second vulnerability is caused by an error in the kernel, which could allow attackers to gain elevated privileges and bypass sandbox restrictions.”
According to McAfee's Marcus, these flaws were the same ones used by Jailbreakme to remotely jailbreak Apple devices.
Mobile flaws
The vulnerability in Apple's iOS is the latest in a series of security bugs identified in mobile devices over the past week.
Security experts at a hacking conference last week pointed out several vulnerabilities in Google's operating system for mobile phones and tablet PCs.
"We shouldn't be surprised to see security bugs happen in very complex software," said Kevin Mahaffey, chief technology officer for mobile security firm Lookout.
Mahaffey said he was not aware of any incidents in which criminals had exploited the bug to gain control of an Apple device, but said the electronics maker has yet to offer a remedy to protect against such attacks.
"Everybody - both good and bad - knows how it works," he said.
Apple said the company was aware of the report and was investigating.
From around the web
Flaw? iPhone?
Does not compute.
By Lacrobat on 4 Aug 2010 ![]()
But only Windows is insecure?
Myth busted.
By cheysuli on 4 Aug 2010 ![]()
Adobe!!
Obviously the security holes in Flash somehow made it over to the ios.
By vikarmo on 4 Aug 2010 ![]()
I second that
yeah this is something to do with Adobe's laziness. It's the only answer to this preposterous claim
By TimoGunt on 4 Aug 2010 ![]()
Simple fix
Jailbreak and install PDF Loading Warner
Until Apple can be bothered to fix this glaring security hole this is the only way to ensure your phone is safe from malicious attack.
By neilwar1 on 4 Aug 2010 ![]()
Apple have fix
Apple have now fixed this and will be rolling out an update soon.
Anyone wanting to JB a new bootrom 3GS or iPhone 4 should do so now and make sure your blobs are on file.
By neilwar1 on 5 Aug 2010 ![]()
Who'd want to hack an i(diot)pone or ipaedo, they're not powerful enough to do anything and the users are unlikely to have any important or worthwhile data on them.
By dodge1963 on 10 Aug 2010 ![]()
advertisement
- How to install Internet Explorer 9
- Maintaining and supporting IE9
- Plan your deployment
- Creating a custom browser package
- Search in corporate environments
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
- Amazon Kindle Fire review: first look
- Lytro light-field camera: first look
- Paying for your crimes with Bitcoin
- Pavement hacking: What it is and how to avoid it
- Google's risky pre-loaded pages
- Mac under attack: how secure is Apple's OS?
- Has your browser been hijacked?
- Can you send a truly anonymous email?
- Is it safe to send bank details over email?
- Sainsbury's Bank bans password storage
- MobileMe triggers credit card blocks
- How to stay safe against session hijacking
advertisement
