Exploit Code for iPhone Jailbreak Hits the Web

· by · News

Following Apple’s release of the iOS 4.0.2 and 3.2.2 security updates Wednesday afternoon, the code for the exploit they protect against went public. Comex, the hacker that used the exploit to build a jailbreak for iOS 4, alerted the public to the code through Twitter.

A flaw in the way Apple’s iOS handled PDF documents could allow an attacker to gain control over an iPhone, iPod touch or iPad and run other code. That’s what Comex did to jailbreak devices so users could install third-party apps that aren’t available through Apple’s iTunes-based App Store.

That same security flaw could, however, be used for more malicious purposes such as stealing or deleting user’s data.

The patch Apple released Wednesday afternoon should protect users from the exploit, although it also means people that have already jailbroken their device will lose access to the unapproved apps on their device. Users hoping to jailbreak their iPhone, iPod touch or iPad after installing the security update will be out of luck, too.

Even though the patch kills jailbreak support, it’s still a good idea to install it because of the serious nature of the exploit.

To update to iOS 4.0.2 on the iPhone 3GS, iPhone 4 and second or third generation iPod touch, or iOS 3.2.2 for the iPad, connect your device to your computer and launch iTunes. You should see a prompt asking you if you want to download and install the update.

[Thanks to Computerworld for the heads up.]

Jeff Gamet

Jeff Gamet

Jeff is the Mac Observer's Managing Editor, and co-host of the Apple Context Machine podcast. He is the author of "The Designer's Guide to Mac OS X" from Peachpit Press, and writes for several design-related publications. Jeff has presented at events such as Macworld Expo, the RSA Conference, and the Mac Computer Expo. In all his spare time, he also co-hosts the We Have Communicators podcast, and makes guest appearances on several other podcasts, too. Jeff dreams in HD.

Sign Up for the Newsletter

Enter a valid email address

Join the TMO Express Daily Newsletter to get the latest Mac headlines in your e-mail every weekday.

Adding to list…

2 Comments

Khaled

take it “eeze”

computerbandgeek

In order to stay protected from this exploit while maintaining your jailbreak, remain on the 4.0 or 4.0.1 firmwares, jailbreak using jailbreakme.com, and install the newly released “PDF Patch” by Jay Freedman (saurik) using Cydia.

If you have a first gen iPhone/iPod touch, it appears that Apple doesn’t give a rat’s (face) about you. The only way to keep your device secure is to jailbreak and install the PDF patch.

Add your comment

Remember my personal information

Notify me of follow-up comments?