All the latest UK technology news, reviews and analysis

Apple patches iOS jail-break vulnerabilities

by Shaun Nichols

More from this author

12 Aug 2010

Comments: 4

  • Tweet this
Apple iPhone 4
Apple has patched two high-profile iOS flaws

Apple has issued an update to patch the iOS vulnerabilities disclosed earlier this month by iPhone 'jail-break' researchers.

The company posted updates for the iOS 4 software used by the iPhone and iPod touch and the iOS 3 firmware used by the iPad.

Both updates are distributed through iTunes, and can be installed by connecting the device to a computer running the application.

The updates block remote code execution flaws in the iOS PDF viewer and IOSurface components which can be exploited through specially crafted web pages.
The vulnerabilities were discovered by a group of researchers from the iPhone Dev Team, which used the flaws to provide a way to remotely jailbreak iPhone 4 handsets and allow the use of applications not approved by Apple.

While the vulnerabilities were not being actively exploited, users were left vulnerable to attack should a malicious developer choose to adapt the procedure for a malware installation.

Michael Price, senior Latin America operations manager at McAfee Labs, told V3.co.uk that the patches should protect users from attack.

"This update should prevent malicious attackers from exploiting these issues, as well as prevent the jail-break technique from continuing to work," he said.

"Testing and verification of the fixes will be required in order to verify with certainty that the issues have been resolved. Also, while many devices will be updated and will no longer be affected, some (or many) will remain unpatched and at risk."

The iPhone Dev Team is warning users of jail-broken handsets not to install the update until a workaround can be developed.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Project Manager -Commodities,Oil,Gas,Agriculture,Power- £90,000

Project Manager, London - Software Solutions (Project...

Project Manager - Hampshire - up to £32K FTC

Project Manager - Hampshire - up to £32K - Fixed Term...

Senior Customer Support Consultant - 2nd/3rd Line Support - SAS

Senior Customer Support Consultant - 2nd/3rd Line Support...

Front Office Application Developer - Investment Banking - Londo

C++/C#/Java developer for a global investment bank within...

To send to more than one email address, simply separate each address with a comma.