Comex releases iOS PDF-exploit source code

Security

Comex, the developer of the jailbreakme.com 2.0 website, has released the source code for the PDF exploit found in un-patched versions of Apple’s iOS mobile operating system. The code has been called “impressive” and “dangerous” by some security analysts. The exploit has the ability to install malicious code on a users iOS device by simply visiting a webpage crafted to run the code. If you do not plan on jailbreaking your iOS device, we recommend updating to iOS 4.0.2 to remove the vulnerability. If you are already jailbroken, we suggest installing the “PDF Fix” patch from Cydia.

[Via Macworld]

Read

16 Comments
  • DInc

    unrevoked….forever.

  • Android

    Best to stick with Android. No huge security holes to be found here!

    • Tim

      BWAH HAHAHAHAHAHAHAAHAH!

  • iCydia

    PDF Patch from Cydia applied :-)

    Thanks BGR!

    • Abhishek

      You speak the truth. Had to root my N1 (AT&T 3G) to get tethering and Cyanogen ROM installed. I find jailbreaking iPhones easier.

  • Iron

    You don’t have to jailbreak android to set it up as free tethering and wifi or to customize beyond stock possibilities….oh wait ROOOOOOOT

    • the doctor

      Say hi to Steve Jobs for me :) .

  • sam

    I still don’t understand why peoples NEED use jailbreak app on an iphone 3/3G/….etc?

    • Logicknot

      You can get some cool stuff customization wise. to make your iphone experience more your own. You know how you can get imageblinds for windows to change the appearance you can do the same thing with winterboard as well as add more functions like a drop down that android has.

      Thats the main thing that i have found for jailbreaking. Making your own preferred user experience.

      • sam

        Oh true. I agree.

    • Bobby Dee

      I did it to unlock and use prepaid from AT&T or Tmobile. I have an Evo now, but I still have my 3GS and 1G iphones, both jailbroken and unlocked using prepaid.. I couldn’t afford two additional $80+ iphone plans from AT&T for the occasional call.. Plus I can run NES for games.

  • Unknown

    We bought the phone let us do what we want to them iPhone or android!!!!!

  • Logicknot

    Here is a link to the patch on modmyi.com http://modmyi.com/cydia/package.php?id=27029 its actually called PDF Patch (CVE-2010-1797) not PDF Fix

  • Noah the Boa

    PDF Patch installed!!

  • Obj_me

    Glad it’s here…figured it would be coming soon so we wouldn’t need to update and loose our our JB to be secure…thanks saurik!

  • http://jemmy Uriel jemmy

    Jemmy

blog comments powered by Disqus