rss twitter

Experts Warn of PDF Exploits on iPad

The iPhone, iPod touch, and the iPad all contain a critical security flaw, according to Germany’s Office for Information Security (BSI), one that is open for exploitation by malicious hackers. Evidently, there is a weakness in the way that iOS devices handle certain websites and PDFs so that potential attackers can gain full access to users’ systems and wreak havoc with just one mistakenly-opened file.

Experts are urging consumers not to open any PDF files from users who they don’t recognize, and the BSI has reportedly been in touch with Apple about the problem, though Apple has not yet issued a comment.

Adobe, the company originally responsible for creating the PDF file format back in 1993, was quick to place the blame on Apple’s PDF-viewer, Preview, from which the security issues appear to originate. They insist that Adobe Reader is currently free from concerns about security and privacy. It’s not really their concern anyway, despite public perception, because the PDF became an open standard back in 2008.

While security advocates are brazenly sounding the alarm, it’s interesting to note that the vulnerability was originally exposed by Comex, the developer responsible for the fairly popular new Jailbreaking site JailBreakMe.com. Comex’s browser-based jailbreaking solution actually utilizes this very exploit to gain access to users’ system files. Far from being a party to potentially malicious hackers, however, the jailbreak community already has a fix in their unofficial app store Cydia that closes the PDF vulnerability that is afflicting the stock hardware. It’s actually safer to be jailbroken!

The net result is that users who were planning to jailbreak their iPad hardware had better do it quickly, because it’s likely that Apple is going to close this particular loophole fairly soon. With the black eye its public relations department has taken recently over the iPhone antenna debacle, the last thing Apple needs is more concerns about the safety and usability of its products.

Leave a Reply

You must be logged in to post a comment.