SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Apple patches critical flaws in iPhone, iPod Touch

Apple patches critical flaws in iPhone, iPod Touch

By:  Gregg Keizer  On: 03 Feb 2010 For: Computerworld Creator

The new iPhone operating system update addresses five bugs, one of which was a memory corruption problem that would have let hackers with physical access get at user's data. This is not the first time Apple Inc. had a problem with its password locking features.

Apple Inc. (NASDAQ:AAPL) has patched five vulnerabilities in the iPhone's operating system, including one in a password-locking feature that's required attention before.

iPhone OS 3.1.3 , the first update since September 2009, addressed five bugs, three of which were tagged with the phrase "arbitrary code execution," Apple-speak for a critical vulnerability. Unlike other software makers, such as Microsoft Corp. (NASDAQ:MSFT) and Oracle Corp. (NASDAQ:ORCL), Apple does not rank flaws with a threat-scoring system.

The vulnerability that stood out to Andrew Storms, director of security operations at nCircle Network Security, was the one in the iPhone's recovery mode, which is used to restore the smartphone when it's completely unresponsive. "A memory corruption issue exists in the handling of a certain USB control message," said Apple 's advisory. "A person with physical access to the device could use this to bypass the passcode and access the user's data."

In other words, data on a lost, but locked, iPhone could be accessed by whomever finds it.

Storms pointed out that Apple patched a vulnerability in recovery mode last September when it updated the iPhone OS to 3.1.1 . At the time, Apple's description of the flaw was similar to today's copy: "A heap buffer overflow exists in Recovery Mode command parsing. This may allow another person with physical access to the device to bypass the passcode, and access the user's data."

Apple has had problems with the iPhone's password-locking feature in the past. In August 2008, a researcher discovered that Apple had forgotten to patch a bug that let people sidestep locking by simply tapping "Emergency Call" on the password-entry screen, then double-tapping the Home button. The bug had been patched in January 2008, but resurfaced in iPhone 2.0. Apple re-patched it a month later.

The other four holes plugged today aren't much to worry about, said Storms. "The small number is a good sign," he said. "Plus, we're not seeing horrendous WebKit vulnerabilities that could be exploited by getting people to a Web site." WebKit is the open-source browser engine used by Apple to power Safari on the iPhone and iPod Touch.

One of the two WebKit bugs is in how the browser engine deals with HTML 5 external resources, such as images or video files. "The sender of an HTML-formatted e-mail message could use this to determine that the message was read," said Apple's advisory.

"That's a marketing or spammer kind of tool," said Storms, equating it with the practice of inserting images in e-mail to monitor the rate at which victims read the spam.

With the appearance of iPhone 3.1.3 -- and the recent unveiling of Apple's iPad by CEO Steve Jobs -- Storms expects that the next update of the smartphone's firmware won't take place until this summer, when a major upgrade will likely be launched alongside a new iPhone. "We're looking later in the year, I think," he said.


Sign up for our Newsletters












Print |  Views: 6725   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




gregg keizer Gregg Keizer is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Is Apple testing a new iPhone model?
Is Apple testing a new iPhone model?A software analytics program has picked up usage logs that might indicate the existence of an Apple iPhone 3.1 device. Find out all the details
Too hot to handle – Apple issues warning about overheating iPhone 3 GS
Too hot to handle – Apple issues warning about overheating iPhone 3 GS It's not just the sales of Apple's new smartphone that's heating up. Some users have reported discoloration of the iPhone's back cover due to the device running very hot
Mac hacker IDs possible iPhone bug
Mac hacker IDs possible iPhone bugAttacker would need a working exploit first, but then could remotely read text messages and other data, says hacker Charlie Miller
Back door or not, Apple App Store means more work for CIOs
of course apple has a back door to its apps store. if you’re using an iphone, it’s steve jobs’ world: you’re just computing in it. the

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.