TaiG jb for iOS 8.x seems to have a broken setreuid() that allows root privilege escalation. Less a backdoor than a broken kernelpatch
This means that the application "can theoretically have access to everything" on your device.
Hopefully the new version of jailbreak fully addresses the problem.
Saurik posted his thoughts on the matter yesterday:
I already talked to TaiG about this awkward kernel patch days ago, and have this on my schedule of things to fix "next" (after the thing I'm working on fixing right now). FWIW, I did not realize their patch was this bad (I mean, dude: that's pretty bad...), but I'm still not terribly concerned (as an example: i0n1c says "don't install tweaks from random people in the next few days", but those already by definition have privileged access, so you should already be careful installing them). (This setuid bug is the "proactive fix" that I talked about in the Cydia 1.1.18 changelog.)
Here's the changelog for the new version of TaiG.
Changelog: ● Fixes setreuid patch to prevent applications from obtaining to root privileges through setreuid. ● Increases stability.
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (14)
Comments are closed for this article.
0
iProService - July 2, 2015 at 9:36pm
How do we fix if jailbroken already using 2.2? There does not appear to be a patch in Cydia.
0
LKai - July 3, 2015 at 7:59pm
Check the repo apt.saurik.com , there should be TaiG tool
0
Saul Hernandez - July 2, 2015 at 7:06pm
I miss evasion jb because this kind of errors never happened due to a full series of test before release, jb fron them were slow to release but more confident
0
Guest - July 2, 2015 at 5:38pm
For users who have jailbroken their devices with TaiG Jailbreak Tool V2.0.0, update TaiG 8.1.3-8.x Untether through TaiG source (apt.taig.com) or 3K source (apt.3kzhushou.com). There is no need to jailbreak again
0
LKai - July 3, 2015 at 8:07pm
No no, it's from basic cydia package Cydia/Telesphoreo apt.saurik.com . Apt.taig only for install or uninstall 3K Assistant
0
Kennorth - July 2, 2015 at 4:48pm
I tried the TaiG 2.2.0 for IOS8.4 at 60% it get black screen and hang.
Then Downloaded TaiG2.2.1 , it also stuck on 60% couple of time it restart the phone and on 3rd and fouth it give 1101
0
kaygwapo - July 2, 2015 at 11:05pm
Turn on the airplane mode. Be sure to respond to "trust this computer" if it appears.
0
Connor - July 2, 2015 at 4:20pm
An update didn't appear for me, how do find it?
0
Inferno - July 2, 2015 at 3:57pm
TaiG already took off version 2.2.1 from their website .........
0
Lebron James - July 2, 2015 at 4:01pm
it's still there..just checked. http://www.taig.com/en/#download-table
0
Vince Carter - July 2, 2015 at 3:42pm
Ok. How about those already jailbroken?
0
Lebron James - July 2, 2015 at 3:54pm
Open up Cydia and go to the Changes tab. The update should appear.