Skip the navigation

Apple leaves iPad vulnerable after monster iPhone patch job

Monday's iOS 4 patches record 65 bugs; iPad won't get fixes until the fall

June 22, 2010 02:03 PM ET

Computerworld - As part of Monday's iOS 4 upgrade, Apple patched a record 65 vulnerabilities in the iPhone, more than half of them critical.

Apple released iOS 4 for the iPhone 3G and 3GS, and the second- and third-generation iPod Touch on Monday shortly after 1 p.m. Eastern time, 10 a.m. Pacific time.

However, the first-generation iPhone and iPod Touch, as well as the much newer iPad, may be vulnerable to some or all of the 65 bugs. The new iOS 4 operating system, which launched yesterday, can't be installed on 2007's iPhone and iPod Touch, and the upgrade is not slated to reach iPad owners until this fall.

The bug count is a record for Apple's iPhone, surpassing the previous high mark of 46 vulnerabilities patched last summer with iPhone OS 3.0.

Formerly known as iPhone OS 4, iOS 4 included patches for 35 bugs, or 54% of the total, that were tagged with the phrase "arbitrary code execution," which is Apple's way of saying the vulnerability is critical and could be used to hijack an iPhone or an iPod Touch. Unlike other software makers, such as Microsoft, Apple does not rank flaws with a threat-scoring system.

Most of the patched vulnerabilities were in WebKit, the open-source browser engine that powers Safari on Apple's mobile devices, as well as Safari for Mac OS X and Windows, and Google's Chrome browser.

Among the 50 WebKit vulnerabilities addressed in iOS 4 was the one used by the two-man team of Vincenzo Iozzo and Ralf-Philipp Weinmann to hack an Apple iPhone 3GS in five minutes at the Pwn2Own contest in March. TippingPoint's 's Zero Day Initiative (ZDI) bug-bounty program paid the two researchers $15,000 -- a record amount for the four-year-old Pwn2Own contest -- for the Safari bug and exploit they used to break into the iPhone.

Apple had patched the same bug in the desktop edition of Safari on June 7, when it rolled out a record-setting 48-patch update as part of Safari 5.

The 15 non-WebKit patches included a pair that addressed glitches in the password-locking feature of the iPhone and the iPod Touch.

Apple has had problems with the iPhone's password-locking feature in the past. In August 2008, a researcher discovered that Apple had forgotten to patch a bug that let people sidestep locking by simply tapping "Emergency Call" on the password-entry screen and then double-tapping the Home button. The bug had been patched in January 2008, but it resurfaced in iPhone 2.0. Apple repatched it a month later.

In February 2010, the last time before Monday that Apple updated the iPhone's firmware, the company fixed another passcode flaw, which could be used to bypass the security feature when a user was restoring an unresponsive smartphone.

It's unclear how many, if any, of the vulnerabilities patched this week affect Apple's iPad. Although the iPad isn't slated to receive the iOS 4 update until sometime this fall, the media tablet runs an interim version of the operating system, dubbed iPhone 3.2, that followed the February iPhone 3.1.3 security update. It's possible that some of the bugs patched Monday were fixed by Apple before it launched the iPad in early April.

But according to the CVE (Common Vulnerabilities & Exposures) database, it's likely that many of the flaws fixed yesterday still exist in the iPad's iPhone 3.2 operating system.

Searches of the vulnerability identifiers listed in Monday's security advisory revealed that eight of the 15 non-WebKit bugs were added to the CVE database in early May, a full month after the iPad's debut. Five others were patched by Apple in Safari and Mac OS X updates issued in late March, just days before the iPad went on sale.

Owners of iPhones and iPod Touches can wait out the update interval -- iTunes automatically checks Apple's update servers once a week -- or retrieve iOS 4 manually by selecting "Check for Update" under iTunes 9.2's Help menu and then docking the iPhone or iPod Touch to a PC or Macintosh.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@ix.netcom.com.

Read more about Macintosh in Computerworld's Macintosh Topic Center.



Our Commenting Policies
Consumerization of IT: Be in the know
consumer tech

Our new weekly Consumerization of IT newsletter covers a wide range of trends including BYOD, smartphones, tablets, MDM, cloud, social and what it all means for IT. Subscribe now and stay up to date!