Published on Mac|Life (http://www.maclife.com)


iPhone Bug Could Circumvent App Store
Created 2008-11-12 17:29

HOLIDAY BUYING GUIDE
    • 10 1337 Gifts for H4x0r World Domination
    • 10 Gifts for the Mac Switcher
    • 10 Creative Gifts for Designers

    Sponsored
SEE MORE ARTICLES

FEATURES
  • iTunes Power Tips Every Mac Owner Should Know
  • The Complete iMac History -- Bondi to Aluminum
  • New Apple Products--as Imagined by the Elite Gadget Press
  • Satire: 10 Ideas Steve Pitched to Disney
  • 50 Common Mac Problems Solved
SEE MORE FEATURES
TOP STORIES
  • iPhone Captures 17% of Smartphone Market
  • New Macs! Redesigned White MacBook, LED iMacs, Mac mini Refresh, and a Magic Mouse
  • 69 Awesomely Free Snow Leopard Compatible Apps
  • Fifth-Generation iPod nano
  • Screencast Video: Create 3D Photo Effects in Final Cut Pro
SEE MORE TOP STORIES
News
iPhone Bug Could Circumvent App Store
Posted 11/12/2008 at 7:29:41pm | by John Pitko
  • commentComments
  • printPrint
  • emailEmail
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Slashdot
  • MacBlips

iphone

With update 2.2 possibly coming soon for the iPhone, hopefully there will be a quick fix to an app-related bug that threatens iPhone security.

TechCrunch reports that there is a serious security hole in the image file "Default.png." The Default.png is displayed when an application is loading on the iPhone.

While the png loads, developers could issue commands to the iPhone that tricks the iPhone's code signing mechanism. Besides giving developers a back door to updating their software that circumvents the the iTunes App Store, the hole could trick the iPhone into believing that malicious code is from a trusted source.

Sounds scary right? Well, it seems the bug is one of many that allows developers to bypass the Apple screening process. So far none has been exploited.

Regardless, let's hope that Apple squashes these bugs with the next update. Just in case.

COMMENTS: 0
TAGS:  App Store, Security
  • commentComments
  • printPrint
  • emailEmail
  • Delicious
  • Digg
  • StumbleUpon
  • Reddit
  • Slashdot
  • MacBlips
COMMENTS
  • Login or register to post comments

Source URL: http://www.maclife.com/article/news/iphone_bug_could_circumvent_app_store

Links:
[1] http://www.maclife.com/article/news/iphone_bug_could_circumvent_app_store
[2] http://www.techcrunch.com/2008/11/11/iphone-exploit-undermines-app-store-security-lets-devs-update-and-run-arbitrary-code/