PDF Exploit Patched in iOS 4.0.2

This time last week, Apple released the second revision to its iOS4 mobile operating system. This incremental update is focused entirely on patching a security vulnerability associated with Safari’s handling of PDF files. Under the previous iterations of the OS, a malicious PDF file could break through security by exploiting and subsequently crashing the Compact Font Format Handler in Safari. Introduced alongside comex’s fairly innocuous web based “JailbreakMe” exploit, this vulnerability has raised several security concerns. Though the jailbreak is legitimate, the same PDF exploit easily opens the gateway to malicious attacks which could put a user’s data and hardware at risk. Though no such attacks have been reported, a user would merely have to open a PDF to put themselves at risk.

Sensing the potential danger, and attempting to maintain their grasp over unlocked phones, Apple was quick to roll out an update. Though this update fixes the Safari security vulnerability, it also disables any “extra” features users may have enabled on their devices. While the update weighs in at a sizable 500MB, it addresses no other issues besides the Safari exploit. Users experiencing other issues under iOS4 will unfortunately have to wait until iOS 4.1 before their problems are further addressed.

Releasing a fix for iPad users as well, Apple has updated the iPad’s OS to version 3.2.2. Both updates can be easily downloaded through iTunes. Upon syncing your device, you should be automatically prompted with a message alerting you to the update. As always, we recommend backing up your device before performing a software update.

Similar Posts

  • Apple Releases Safari 5

    With Apple’s announcement of the revolutionary iPhone 4 yesterday, it would be easy to overlook the release of Safari 5 that coincided with it. While certainly not as glamorous as Apple’s latest device, the newest version of Safari does bring some changes that will give it a serious leg up in the browser wars.

    Performance is easily the biggest deciding factor when choosing a browser, and Apple has upgraded Safari with a faster “Nitro” engine to keep themselves ahead of the game. Apple claims Safari 5 will run JavaScript 30 percent faster than Safari 4, 3 percent faster than Chrome 5.0 and more than twice as fast as Firefox 3.6.

    In addition to significant speed boosts, Safari 5 also includes the Safari Reader. This utility automatically detects if you are browsing a page with an article on it, and allows you to view it in a continuous and clutter-free manner. To enable Safari Reader, simply navigate to an applicable page and click the Reader icon in the Smart Address Field. Upon doing so, onscreen controls, similar to those seen when viewing a PDF, will appear and let you email, print, and zoom. Safari Reader even saves text settings so font size is the same if you revisit the page.

    Though not apparent by simply glancing at the UI, Safari 5 also includes a robust set of HTML5 tweaks under the hood. The new browser brings over a dozen new features including full-screen mode and closed captioning for HTML5 video as well as HTML5 geolocation. To view some examples of the HTML5 web standard in action, check out Apple’s showcase of demos here.

    Other more subtle refinements include DNS prefetching and improved catching. DNS prefetching means that if you are viewing a web page with links, Safari detects them and looks them up behind the scenes. When you click a link, the page loads faster as a result. A web cache is essentially an index of pages previously viewed. Since Safari 5’s cache has been expanded, more pages fit into it and load faster upon being revisited.

    Appending the aforementioned features are other upgrades such as a smarter address field, integrated Bing search, hardware acceleration for Windows and an improved web inspector. Safari 5 is available today, and is a free download for Mac + PC. Download it here.

  • Apple Donates MacPaint Source Code

    I’m going to date myself here: I wasn’t around for the release of MacPaint in 1984. While I didn’t get to use the…

  • Mac OS X 10.5.5 Update Released

    Many thanks to Powerpage for the rundown of updated features. General: Includes recent Apple security updates. Addresses stability issues with video playback, processor…

  • 2TB Time Capsule Announced!

    Apple has added a 2TB Time Capsule to their line today, and it’s available for $499—the former price of the 1TB Time Capsule….

  • iOS 4.3 Released Today

    Apple released the latest version of their mobile operating system iOS 4.3 today.  This is a free download and contains some exciting new…