You are here: silicon.com > Hardware > PDAs

PDAs

iPhone 3.0 patches 46 security holes

Apple attack

Tags: 3.0 os, iphone, apple

By Matthew Broersma

Published: 19 June 2009 08:53 GMT

Apple has patched nearly four dozen security holes in the iPhone and iPod Touch with its iPhone OS 3.0 release, made available on Wednesday.

The 46 flaws could allow an attacker to bypass security restrictions, shut down an application, disclose sensitive information, conduct cross-site scripting and cross-site request forgery attacks, or take over the device, Apple said in an advisory.

Independent security firm Secunia ranked the most serious of the vulnerabilities as "highly critical".

Several of the bugs could allow a hacker to execute malicious code on the handset. For instance, vulnerabilities in the CoreGraphics component could be used to launch an attack when a user views a specially crafted image or PDF file.

Similarly, certain flaws in the web-browsing framework WebKit could let an outsider run code if the device's owner visits a malicious website.

A number of the vulnerabilities, mainly found in WebKit, open the door to cross-site scripting attacks, where the hacker compromises the phone by injecting code into a seemingly safe website.

In addition, bugs in Safari could lead to the disclosure of the search history and to successful 'clickjacking' attacks. Clickjacking is a technique where the intruder tricks the user about what they are launching when they click on an area, leading them to carry out an unintended action, such as approving a purchase.

Some of the vulnerabilities are more unusual, such as a flaw in Mail that makes it possible for an outsider to initiate a phone call without needing the user to do anything. Another is a bug in WebKit that could permit websites to surreptitiously track users.

Besides the security fixes, iPhone OS 3.0 adds functionality such as system-wide search and cut-and-paste. The software, first shown off to developers in March, is available via iTunes.

Original article: Apple stamps out 46 iPhone bugs from ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bethan Jones Can I use a netbook as my everyday work machine? Part II silicon.com sub editor reveals whether her netbook delivered

Seb Janacek Magic Mouse - Apple's best ever? Minority Report: After years of disappointment, one Mac lover has hope


  • Jobs
Web Tester - Penetration Tester - Staffordshire West Midlands

Candidates must have thorough experience of web application penetration testing which include both knowledge and experience in Man in the Middle ...

Oracle Database Administrator - Essex

It is preferred that the candidate has the following Technical Skills: OCP, RAC, 11g, Oracle reports server, Conversant with windows OS and Shell ...

Production Support & Oracle DBA

Shell Scripting The Oracle DBA will have the following soft skills: " Excellent communication skills " Proactive and enthusiastic " Able to work as ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: