April 28, 2024
iPhone Vulnerability Makes It Easy to Access Your Pin Protected Data

iPhone Vulnerability Makes It Easy to Access Your Pin Protected Data

Posted May 27, 2010 at 11:31am by iClarified
A data protection vulnerability has been discovered with non-jailbroken pin protected 3GS iPhones that bypasses authentication and accesses data

The vulnerability was discovered by Bernd Marienfeldt and applies to various firmware versions.

This data protection flaw exposes music, photos, videos, podcasts, voice recordings, Google safe browsing database, game contents… by in my opinion the quickest compromising read/write access discovered so far, without leaving any track record by the attacker. It's about to imagine how many enterprises (e.g. Fortune 100) actually do rely on the expectation that their iPhone 3GS's whole content is protected by encryption with an PIN code based authentication in place to unlock it.


The contents sample have been collected off a non jail broken iPhone 3GS (with latest iPhone OS installed, all apps fully up to date and immediately PIN lock enabled) by simply connecting it powered off via USB to a Linux Lucid Lynx PC (10.04) and then switched back on – being automatically mounted with given insecurity and never been attached to the PC before.


Merienfeldt believes the allowed write access could also lead into triggering a buffer overflow. Apple thinks they understand why this can happen but cannot provide timing or further details on the release of a fix.

Read More [via Robert]


iPhone Vulnerability Makes It Easy to Access Your Pin Protected Data


Add Comment
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
iClarified Icon
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (5)
You must login or register to add a comment...
George
George - May 27, 2010 at 12:41pm
They can close any holes for jailbreak / unlock and leave exposed such info?? They should spend more time to make it safer and not trying to close such holes.
Hulu
Hulu - May 27, 2010 at 1:31pm
Yes, you can get more security protection for your iPhone by jailbreaking methods. Yeah, I am damn serious, you can ask Steve Jobs for sure. Here is his e-mail: sjobs@apple.com (no longer sjobs@gmail.com after AdMod skirmish)
Anonymous
Anonymous - May 27, 2010 at 3:54pm
Um...this isn't news. You've always been able to access the media partition. Just use iFunbox or DiskAid. And access to the media partition doesn't mean you can run unauthorized code, so I fail to see how a buffer overflow could be possible. Nothing more than scare tactics here.
Nathaniel
Nathaniel - May 27, 2010 at 8:41pm
This is being performed on a pin-locked device. You shouldn't be able to view this information unless the phone is unlocked
BRIKZ
BRIKZ - May 31, 2010 at 7:38am
That is why he anonymous by the way.....
Recent. Read the latest Apple News.
RECENT
Tutorials. Help is here.
TUTORIALS
Where to Download macOS Monterey
Where to Download macOS Ventura
AppleTV Firmware Download Locations
Where To Download iPad Firmware Files From
Where To Download iPhone Firmware Files From
Deals. Save on Apple devices and accessories.
DEALS