• On CBS.com: The Bro Code
advertisement
November 12, 2008 12:00 AM PST

iPhone Security Flaw May Allow Apps to Execute Arbitrary Code, Bypass Approval

Posted by Ben Wilson

Developers of third-party iPhone Apps may have a way to circumvent Apple's iTunes App Store approval process for their updated Apps by executing arbitrary code from within their own applications whenever they choose to do so.

The newly discovered exploit reveals itself via a technique discovered by developer Patrick Collison and is documented on his blog. Essentially, Collison, discovered a workaround that allows for the display of dynamic default.png images. These images load whenever apps are launched on the iPhone. An Xcode Project demoing the exploit can be downloaded and a video demoing the exploit can be found on the blog.

Some developers believe that this feature would be of utility to programmers, others deem it a flaw because it can be used as an exploit to update and execute arbitrary code regardless of content whenever the developer chooses to do so.

How Apple decides to handle this issue remains to be seen. Since this flaw could be used by the developer to circumvent the App Store's approval process, the company may choose to close eliminate the dynamic-image functionality and hence close the hole.

Currently there is no evidence that any third party App has taken advantage of this exploit to run any malicious code.
Recent posts from iPhone Atlas
Hoover's lays out mobile apps for business pros
AT&T Testing Enhanced Faster 3G
WebEx comes to the iPhone
Pandora 2.0 for iPhone released
Apple activates iTunes downloads over 3G, with a caveat
Macworld Keynote: iPhone Highlights
AT&T 3G Upgrades Reportedly Degrade EDGE Service
Best Buy offers refurbished iPhones
advertisement

About iPhone Atlas

iPhone Atlas helps you navigate the ins-and-outs of Apple iPhone ownership with how-tos, troubleshooting information, news, reivews, and more.

Add this feed to your online news reader

iPhone Atlas topics