Security Bytes

Aug 4 2010   4:25PM GMT

iPhone jailbreaking exploit sparks mobile security concerns

Marcia Savage Marcia Savage Profile: Marcia Savage

Jailbroken phones are more prone to security threats, researchers say.

The emergence of an exploit used by a website for iPhone “jailbreaking” prompted security researchers to issue warnings about smartphone security.

The website, ┬áJailbreakme.com, allows iPhone and iPad users who visit the site in Safari to jailbreak their devices — obtain applications not authorized by Apple — with a simple slide button, said Graham Cluley, senior technology consultant at Sophos. The website exploits a vulnerability in the way the mobile edition of Safari handles PDF files, he said.

“What concerns me, and others in the security community, however, is that if simply visiting a website with your iPhone can cause it to be jailbroken, just imagine what else could hackers do by exploiting this vulnerability? Cybercriminals would be able to create booby-trapped webpages that could — if visited by an unsuspecting iPhone, iPod Touch or iPad owner — run code on visiting devices without the user’s permission,” Cluley wrote in a blog post.

VUPEN, an IT security research firm, on Tuesday, issued an advisory about two vulnerabilities in Apple iOS for iPhone and iPad that attackers could exploit “to take complete control of a vulnerable device.”

Dave Marcus, security research and communications manager at McAfee, said the vulnerabilities pose the threat of being used for other attacks.

“This should serve as a wake-up call for anyone with a mobile device: Remote exploitation is real and here to stay,” he wrote in a blog post. “For now, these vulnerabilities are being used (as far as we know) to jailbreak iPhones, but they could be used to do many other things to iPhones and their owners around the world.”

 Comment on this Post

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: