Feb 21, 2008

iPhone DoS vulnerability exposed; possible 1.1.3 jailbreak option

Jimmy Shah, a McAfee Avert Labs blogger, recently discovered an exploit in the iPhone’s Safari browser- one that could possibly used to develop a one-step jailbreak for firmware version 1.1.3. Mr. Shah writes,

“The researchers who found the vulnerability were looking for a method to unlock the filesystem on iPhones with the latest firmware (1.1.3). Unlocking the file system allows the installing of custom ringtones and third party applications. With the last firmware version you could automatically unlock your iPhone by visiting a particular website with the Mobile Safari browser.”

He also states the the exploit could be used for malicious purposes, but can be prevented by disabling Javascript in the Safari setting menu on the iPhone. Basically, disabling Javascript renders the exploit useless since evil-doers can’t have the code run automatically. This is good news for the iPhone hacking community, though. It’s only a matter of time before an even easier jailbreak method is released for 1.1.3.
Source...

No comments: