Global Security Watch > Apple to Fix iOS Security Flaw for iPhones, iPads, iPods ...
[DailyFinance] The security vulnerabilities are in Apple's iOS versions 3 and 4 for the iPhone and iPod, as well as iPads running iOS version 3. When customers using the Mobile Safari Web browser land on a malicious website and try to open a PDF document, a hacker can take advantage of a memory corruption error when processing certain data in the document, exploit the flaw to execute arbitrary code, and take over the device.
[Previous] Securing Social Security | The American Prospect...
[Next] Social Security approaches its 75th anniversary | McClatc...
Some related posts from Technorati and Google.
[iLounge | All Things iPod, iPhone, iPad and beyond] Apple has iOS security fix readied | iLounge News: iLounge news discussing the Apple has iOS security fix readied. Find more Apple news from leading independent iPod, iPhone, and iPad site.
[Gizmodo: ipad] Apple Security Breach Gives Complete Access to Your iPhone: The result is that, without any user intervention whatsoever, that program can do whatever it wants inside your iPhone, iPod touch or iPad. Anything you can imagine: Delete files, transmit files, install programs running on the background that can monitor your actions...
[MyCE News, Articles & Reviews] IOS security flaw makes iPhones, iPads, vulnerable to hackers ...: Apple has long prided itself on providing a more secure OS than Windows, but they have had to deal with a recent increase in OS attacks as the iOS platform becomes more popular. Similar to Microsoft, Apple is now being criticized for a slow response to publicly revealed security flaws.
[Iphone Jailbreak | Ipod Jailbreak | Ipad Jailbreak | MacBook | Apple News] Ipod | Apple Ios Security Flaws Put Iphones, Ipads, Ipods At Risk ...: In large part, this development has come since Apple’s iPhone, iPod and now the iPad have gained sizable followings. According to Vupen, the security flaws …
[Express] Express » Your request is being processed”¦ Apple Security Breach ...: The application targeted in such an attack, Alberts noted, is not Adobe Systems Inc.’s Acrobat reader which allows users to view PDF files, but Apple’s internal application for opening those files on its iOS devices.
[iLounge | All Things iPod, iPhone, iPad and beyond] German agency warns of iOS security issue | iLounge News: Find more iPad news from leading independent iPod, iPhone, and iPad site. It is urging users not to open PDF files and only use trustworthy websites until Apple issues a software update;
[Daily IT Newswire] Apple's iOS devices meet enterprise security needs - Page 1 - Security: For companies that need higher level of security, IT can require stronger unlock passcodes, mandate the iOS hardware encryption feature be turned on, make use of certificated-based authentication for e-mail, virtual private network VPN or Wi-Fi access, via Simple Certificate Enrollment Protocol (supported by Apple) and a PKI and SCEP server; application encryption, via new APIs for this purpose in iOS 4 (Jaquith notes that the iPad won't support iOS 4 until some time later in 2010).
[Portable Gadget] German government agency warns of Apple iOS 'two critical weak ...: According to The Bundesamt für Sicherheit in der InformationstechnikGerman (BSI) or Federal Office for Information Security, Apple’s iOS operating system has “two critical weak points for
[D' Technology Weblog] Apple fixes iOS 4.0 “security holes”, Will release update “likely ...: The two security exploits, highlighted by only current web-based iPhone jailbreak, relate to the way iOS web browser, Safari, reads PDF files on iPad, iPhone and iPod Touch. One of the exploits utilizes the methods that Safari uses to .
[TiPb - The #1 iPhone, iPad, and iPod touch blog] Apple investigating web-based exploit used for iOS 4, iPhone 4 ...: If you visit Jailbreakme.com, perhaps, because they are up-front about each step, but what if you get an email with a link to superhappyfuntime.com/evilFile.pdf, click on it in Mail.app, and are jailbroken that way? (Not a real link.) I am not saying these sites are rampant in the wild right now outside of jailbreakme.com, but the point is that such 0-day explots of iOS 4 are possible, and they appear to be simple to create and disguise their intent.
[Quick Hot News] Apple fix for iOS PDF exploit in pipeline - SlashGear (blog): msnbc.com Apple fix for iOS PDF exploit in pipeline SlashGear (blog) Apple has reportedly come up with a fix for the remote PDF exploit that led the German government to issue an official warning about iPhone security. that Apple has developed a software fix for the iOS security hole exploited to enable a Web .
[The Security Blog» Latest InfoSec Threat Research & News | TheSecurityBlog.com] Questions and Answers on the jailbreakme vulnerability - Security ...: A: The credits on jailbreakme.com are as follows: "Jailbreak by comex, website by westbaer and chpwn. Special thanks go out to BigBoss, chronic, DHowett, MuscleNerd, planetbeing, posixninja, and saurik."
[The Mac Security Blog] The Mac Security Blog » iOS Vulnerability Allows Web-Based iPhone ...: But this system, which requires little user intervention, opens up serious risks to iOS devices. The person who discovered this vulnerability should have kept it quiet and contacted Apple, rather than make it public enough that now others can exploit it.
[My Blog] JailbreakMe PDF Exploit to Patched iOS 4.0.2 | My Blog: Apple has developed a fix for iPhone mobile safari browser security hole that allows iPhone, iPod Touch and iPad to visit a Web site JailbreakMe.com, which hosts an exploit code written by comex to bypass digital code signatures used by Apple in all iDevices. The method is being used to jailbreak all iPhone, iPod Touch and iPad including iPhone 4.
[Cult of Mac] Germany Announces iOS Security Warning Over PDFs | Cult of Mac: The issue appears to be with iPhones using iOS 3.1.2-4.01, iPads using iOS 3.2-3.2.1 and iPods touch devices using iOS 3.1.2-4.0, according to the German statement. Earlier this week, hackers built “JailBreakMe”, an exploit of how Safari handles PDF files.
[Blogtech.org - Advanced Technology Views, News & Guides» Blogtech - Advanced Technology Views, News & Guides] Blogtech - Advanced Technology Views, News & Guides | Blogtech.org ...: The hack itself, which exploits the iOS Safari web browser, may not be a security threat to your Apple device, but the implications are pretty bad. As you can jailbreak your device by downloading a PDF file, which hides the hack-code, so can hackers play havoc with this all-too-apparent soft-spot in the OS.
[Mobile Tech Today] Wireless Tech - Germany Warns of Apple iOS Security 'Weak Points': German authorities have expressed concern over an iOS security issue, saying that "weak points" in the operating system could allow criminals to spy on passwords, planners, photos, texts , e-mails and even listen in to phone conversations. Although no attacks have been observed yet they were likely to appear soon, the agency said.
[Technology RSS from The Detroit News] Germany warns of possible Apple security problem | detnews.com ...: "This allows potential attackers access to the complete system, including administrator rights," it added, urging users not to open PDF files on their mobile devices and only use trustworthy websites until Apple Inc. publishes a software update.
Reflected tags on Technorati: Blog, Security, Global Security Watch