JailbreakMe Utilizes PDF Exploit to Jailbreak Your iPhone

JailbreakMe, the latest version of jailbreak tool, is the first browser-based jailbreak tool. Unlike the earlier jailbreak tools such as Spirit, Redsn0w and PwnageTool, you are not required to download any software for the jailbreak. All you need to is to point the Mobile Safari to jailbreak.com and the entire jailbreak process is done within the browser.

I believe many of you have jailbroken your iPhone using JailbreakMe. But you probably do not know what’s going on behind the “Slide to jailbreak” button.

How JailbreakMe works

As widely reported today, VUPEN, a security research company, identified the security flaw in PDF rendering that allows hackers to gain complete control of iPhone. The JailbreakMe actually takes advantage of this PDF exploit found on iOS 4.0/4.0.1 and iPhone OS 3.1.x to make web-based jailbreak possible.

Security researcher from F-Secure Corporation found that the jailbreakme.com site includes 20 separate PDFs for different combinations of hardware and firmware. Depending on the model of iPhone and the OS version, you will download the corresponding PDF file from jailbreakme.com. The PDF file with a corrupted font embedded triggers the PDF exploit that allows full access to the iPhone OS. Jailbreaking and installation of Cydia are the rest of the story.

How to Avoid PDF Attack

While the security flaw allows iPhone Dev team to develop JailbreakMe for iPhone jailbreaking, the bug can also be used by hackers for malicious purposes. Apple said they are aware of the exploit and investigating the issue. However, as of now, there is no fix yet.

To avoid your iPhone from this security flaw, an iPhone developer has developed a utility called “PDF Loading Warner” that displays a warning when mobile Safari loads PDF file from the Internet. It is not a patch for the PDF exploit. The tool is just intended to give you a second thought before opening the PDF file.

About Simon Ng

Founder, developer and chief blogger of simonblog.com

, , , , , , , ,

11 Responses to JailbreakMe Utilizes PDF Exploit to Jailbreak Your iPhone

  1. Joao August 5, 2010 at 3:25 am #

    Apple iPhone 4 32GB Unlocked | MainBids »
    mainbids.com/

  2. Grace August 12, 2010 at 1:35 pm #

    “In its ongoing commitment of providing safer, faster and more stable PDF software tools, Foxit is taking a proactive measure in securing its 100 million PDF Reader users against the iPhone/iPad Jailbreaking application that utilizes malicious PDFs to hack the systems of unsuspecting users. Hackers are now trying to use these malicious PDF’s to access sensitive data on desktops. Foxit welcomes all PDF Reader users to download the latest version of the Foxit Reader 4.1.1 which addresses and resolves the issues related to the jailbreak hack.

    To protect iPhone/iPad users from the jailbreak program that is being used to exploit iPhones in the way they handle PDFs, Foxit is preannouncing its soon to be submitted PDF Reader App for iPhone. Foxit believes that the upcoming release of its Foxit Reader for iPhone will provide a secure PDF reader for the iPhone. Foxit will be submitting this App within two weeks and it will have full PDF viewing capability. Just as with the Windows Reader, Foxit PDF Reader for iPhone will protect users against malicious PDFs.”

Trackbacks/Pingbacks

  1. Soniq.org Links » Don’t Upgrade to iOS 4.0.2 / 4.1 if You Need Jailbreaking - August 6, 2010

    [...] covered by CNet, Apple has already developed the fix to circumvent the PDF exploit, that is utilized by JailbreakMe. Apple spokeswoman said in a statement, “We’re aware of this reported issue, we have already [...]

  2. How To Pimp My iTouch » Blog Archive » Don’t Upgrade to iOS 4.0.2 / 4.1 if You Need Jailbreaking - August 6, 2010

    [...] covered by CNet, Apple has already developed the fix to circumvent the PDF exploit, that is utilized by JailbreakMe. Apple spokeswoman said in a statement, “We’re aware of this reported issue, we have [...]

  3. Jaibreak and Pimp Your iTouch » Don’t Upgrade to iOS 4.0.2 / 4.1 if You Need Jailbreaking - August 6, 2010

    [...] covered by CNet, Apple has already developed the fix to circumvent the PDF exploit, that is utilized by JailbreakMe. Apple spokeswoman said in a statement, “We’re aware of this reported issue, we have [...]

  4. Don’t Upgrade to iOS 4.0.2 / 4.1 if You Need Jailbreaking « Geejenkins's Blog - August 8, 2010

    [...] covered by CNet, Apple has already developed the fix to circumvent the PDF exploit, that is utilized by JailbreakMe. Apple spokeswoman said in a statement, “We’re aware of this reported issue, we have [...]

  5. JailbreakMeでなぜ脱獄できるのか-問題点と対処- - Jailbreakers.Info - August 11, 2010

    [...] utilizes PDF exploit to Jailbreak your iPhone” http://www.simonblog.com/2010/08/05/jailbreakme-utilizes-pdf-exploit-to-jailbreak-your-iphone/ var hatena_bookmark_anywhere_limit = 100;var hatena_bookmark_anywhere_style = true;var [...]

  6. Don’t Upgrade to iOS 4.0.2 / 4.1 if You Need Jailbreaking « Rosiechenzy's Blog - August 12, 2010

    [...] covered by CNet, Apple has already developed the fix to circumvent the PDF exploit, that is utilized by JailbreakMe. Apple spokeswoman said in a statement, “We’re aware of this reported issue, we have [...]

  7. Apple Releases iOS 4.0.2 for iPhone and iOS 3.2.2 for iPad to Patch PDF Exploit | Best Ways To Pimp Your Apple iTouch - August 14, 2010

    [...] a week after the PDF exploit was uncovered, Apple releases iOS 4.0.2 to patch the [...]

  8. Apple Releases iOS 4.0.2 for iPhone and iOS 3.2.2 for iPad to Patch PDF Exploit « Rosiechenzy's Blog - August 19, 2010

    [...] a week after the PDF exploit was uncovered, Apple releases iOS 4.0.2 to patch the [...]

  9. Best Deals On iPhone » An Update about iOS 4.1 Jailbreaking - September 15, 2010

    [...] the earlier PDF exploit that was used by JailbreakMe, there is no easy way for Apple to patch this bootrom-based exploit. [...]

Leave a Reply