Symantec, the US-based security firm, has issued a warning relating to Apple’s iOS which is designed to support the iPhone, iPad and iPod. According to the firm, there is a vulnerability in the iOS which could lead devices wide open to security attacks by remote operation, as hackers take control of devices through the system.
While the threat is currently theoretical, experts at Symantec suggest that Apple needs to address the issue before people begin to realise the weakness and exploit it. The vulnerability comes from the way Mobile Safari deals with Adobe Acrobat PDF documents. According to Symantec, when a user launches a PDF file on their device, there is potential for a hacker to embed some code within the file to infect devices.
Apple have issued a statement saying that they have seen the Symantec report, and are looking in to it.
A security expert from Sophos has commented: “The exploit uses the same principle as Jailbreakme – a utility that lets iPhone 4 owners run non-Apple approved applications – although it uses the exploit in a benign way. It uses the same tricks as you do when jailbreaking. We always thought that Apple’s Mobile Safari would be the main vulnerability. At present, we have yet to see any of these exploits out in the wild, but it is only a matter of time.”
“In an ironic twist, the only way of preventing Mobile Safari from automatically opening PDF files is by jailbreaking a phone and installing an application, called PDF Loading Warner, that then asks for permission every time the browser tries to open a PDF file. I personally wouldn’t want to jailbreak my phone to get the fix.”
“Right now, it’s all eyes on Apple who we hope are going to fix this problem as soon as possible. Historically, Apple have been slow to fix problems on their Mobile browser. This has been a concern of ours in the past and continues to be.”
Related posts:
- Ethical dilemma for Apple iPhone users
- Jailbreaking still an issue for Apple IOS 4.1
- Safari 5 web browser released by Apple
- Attacks list 2009 dominated by Internet Explorer and Adobe Reader
- Is a phone case going to appease disappointed Apple fans?
- WebKit receives process management update from Apple


