Apple Security Breach Gives Complete Access to Your iPhone

August 7, 2010 by admin  
Filed under Security News


128 views   2 Comments

 

 

9972ac1b2b49643a6556aa387b7b2416 Apple Security Breach Gives Complete Access to Your iPhone

 

Right now, if you visit a web page and load a simple PDF file, you may give total control of your iPhone, iPod touch, or iPad to a hacker. The security bug affects all devices running iOS 3.1.2 and higher.

 

Update: Initially we thought that this exploit only effected iOS4 devices, but it turns out all iPhones, iPod Touches and iPads running 3.1.2 and higher are susceptible.

 

The vulnerability is easily exploitable. In fact, the latest one-click, no-computer-required Jailbreak solution for iOS 4 devices uses this same method to break Apple’s own security (although in a completely benign way for the user).

 

How it works

It just requires the user to visit a web address using Safari. The web site can automatically load a simple PDF document, which contains a font that hides a special program. When your iOS device tries to display the PDF file, that font causes something called stack overflow, a technical condition that allows the secret ninja code inside the font to gain complete control of your device.

 

The result is that, without any user intervention whatsoever, that program can do whatever it wants inside your iPhone, iPod touch or iPad. Anything you can imagine: Delete files, transmit files, install programs running on the background that can monitor your actions… anything can be done.

 

This is not the first time that something similar has happened. At the beginning of the iPhone’s life there was a problem with TIFF files that also caused the same security breach. Apple patched the bug after a while, but back then there were very few iPhones compared to the current installed base. Apple says that there are 100 million iPhones, iPod touches, and iPads in the world. Obviously, malicious hackers are racing to get a slice of that market.

 

How can you avoid it?

Right now, the easiest way to avoid this problem is by not going to any PDF links directly and not loading any PDF from any non-trusted source.

 

You can also jailbreak your iPhone and install a program that will ask for authorization every time your browser encounters a PDF (just look for “PDF loading warner” in Cydia).

 

b9f8296e585bd3fac793d5f155fedd03 Apple Security Breach Gives Complete Access to Your iPhone

While this doesn’t solve the security problem at all, at least it will remind you every single time.

 

 

Source :  http://gizmodo.com



Related posts:

  1. JailbreakMe: Apple issues emergency iPhone/iPad security patch
  2. JailbreakMe: Security warning for iPhone and iPad owners
  3. Apple hires jailbreaking iPhone hacker Nicholas Allegra
  4. Sophos iPhone app – free download now available
  5. First iPhone worm discovered – ikee changes wallpaper to Rick Astley photo

Comments

2 Responses to “Apple Security Breach Gives Complete Access to Your iPhone”
  1. Ray says:

    Interesting blog, this one I am certainly going to bookmark. Lots of very interesting content. I have some free software that you can share with your members if you don’t mind. Please can you go to ninjasoftwarecompany.com it would be greatly appreciated if you could give me your opinion.

Trackbacks

Check out what others are saying about this post...
  1. [...] Apple Security Breach Gives Complete Access to Your iPhone [...]



Speak Your Mind

Tell us what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!