New iPhone, iPod Touch 'jailbreak' app patches critical TIFF bug

Free program opens iPhone/iPod Touch 1.1.1 to third-party app installs

Hackers have released a tool that "jailbreaks" up-to-date iPhones and iPod Touches, but unlike previous tools, it doesn't require a Macintosh or PC as a middleman.

As an added bonus, the software, dubbed AppSnapp 1.1.1, patches a vulnerability in the stripped-down Mac OS X that both devices use and that had been exploited previously to unlock iPhones.

Created by a group of nine developers, among them HD Moore of Metasploit fame, AppSnapp opens both the iPhone and iPod Touch and then installs another program,, which in turn can install unauthorized, non-Apple programs. The iPhone and iPod Touch must be running the current firmware, Version 1.1.1, the AppSnapp developers said.

The jailbreak does not unlock the iPhone -- meaning it doesn't open it so that calls can be made using a mobile carrier other than AT&T Inc., the only company sanctioned thus far by Apple Inc. "AppSnapp does not unlock the phone. You will have to use anySIM to do so after you install AppSnapp," according to a FAQ on the AppSnapp site.

Unlike earlier jailbreaks, AppSnapp 1.1.1 can be installed only from the iPhone/iPod Touch built-in Safari Web browser, which eliminates the need to connect the device to a Mac or PC and then run a jailbreak program from the computer.

The utility also fixed a long-standing vulnerability in the iPhone's and iPod Touch's TIFF image-rendering library. That bug, which is shared by Safari, the iPhone's e-mail application and iTunes, had been used to both unlock iPhones and install earlier jailbreak programs. "[AppSnapp] Fixes Apple's TIFF bug, making your device more secure than it was without AppSnapp!" the hackers' site boasted.

Two weeks ago, HD Moore publicized the TIFF vulnerability by posting multiple exploits that he said were "rock-solid" and could easily compromise any iPhone, no matter what firmware it ran.

AppSnapp is available free of charge from the site. Its creators are, however, accepting donations via PayPal.

Copyright © 2007 IDG Communications, Inc.

Shop Tech Products at Amazon