Jailbreak artists exploit unpatched Apple iPhone, iPad bugs
But also provide patch to fix flaws, which Apple will probably do soon, says expert
Computerworld - Developers today said they used a pair of unpatched vulnerabilities in Apple's iOS to "jailbreak" the iPhone and iPad, including the first-ever hack of the iPad 2.
Some security experts immediately said the unfixed flaw -- and the fact it's essentially been released into the wild for miscreants to exploit -- posed a danger to iPhone and iPad owners.
"If they exploited the same vulnerability in a copy-cat maneuver, cybercriminals could create booby-trapped webpages that could -- if visited by an unsuspecting iPhone, iPod Touch or iPad owner -- run code on visiting devices," warned Graham Cluley, a senior technology consultant with U.K.-based Sophos, in a blog post.
To jailbreak an iOS device, users must visit the JailbreakMe website with an iPhone, iPad or iPod Touch running the current version of iOS, then install JailbreakMe 3.0.
The hack was released by a team led by someone identified only as "comex," and is the latest in a string of exploits that have circumvented Apple's App Store-only model, including one issued by the same group last August, just weeks after Apple rolled out iOS 4.
Ten days after JailbreakMe 2.0's 2010 debut, Apple patched the two vulnerabilities used by comex.
Charlie Miller, the only person to win prizes four years running at the Pwn2Own hacking contest, and a principal research consultant for Denver-based Accuvant, said it was likely Apple would react quickly to the newest jailbreak.
"This one is a remote code executable vulnerability," said Miller of one of the two bugs exploited by JailbreakMe 3.0. "Apple will probably patch this in a couple of weeks at the most."
Like Cluley, Miller was concerned by the bugs and exploits. "They're certainly a threat, and would be easy to make malicious," he said.
Miller also noted that because comex released a patch for the vulnerabilities at the same time as JailbreakMe 3.0, the situation wasn't serious. "For anyone worried about security, they can jailbreak their iPhone and then apply the patch," Miller said.
Comex published the fix, dubbed "PDF Patcher 2," on the Cydia app store, a popular site for downloading applications that run only on jailbroken iOS devices.
"Due to the nature of iOS, this patch can only be installed on a jailbroken device," said comex in a short FAQ on JailbreakMe. "Until Apple releases an update, jailbreaking will ironically be the best way to remain secure."
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Infographic: Converged Infrastructure Benefits This Infographic quantifies the savings organizations are realizing from increased deployment speed, higher availability, and lower annual costs.
- CIOs Deliver Productivity Breakthroughs with Intelligent Digital Signage Retailers have long recognized the influence that digital signage provides over a shopper's point-of-purchase decision making process.
- Going Paperless? Here's What You Need to Think About As makers of some of the world's most popular PDF solutions, we often consult with businesses & governmental agencies that have the goal...
- The Big Data Opportunity for HR and Finance If CEOs, CFOs, CIOs, and CHROs want to drive their businesses forward, they will need to quickly recognize the enormous value of big...
- Top 4 Digital Signage Fails Join RMG Networks for a look at four of the most common reasons digital signage fails in corporate businesses. Learn about strategies to...
- Building Tomorrow's Infrastructure Listen to this podcast to discover how Crider Foods worked with PC Connection to update their IT infrastructure, while maintaining compliance and control. All Macintosh White Papers | Webcasts
Our new weekly Consumerization of IT newsletter covers a wide range of trends including BYOD, smartphones, tablets, MDM, cloud, social and what it all means for IT. Subscribe now and stay up to date!