Apple iOS 5.0.1 hacked, untethered via two security holes

Summary: The 'Corona' jailbreak tool latest exploits a pair of iOS security vulnerabilities to bypass Apple's code-signing requirements.

Using two different security vulnerabilities in Apple's flagship mobile operating system, a security researcher has released a tool to untether devices running iOS 5.0.1.

The latest jailbreak, dubbed Corona,  exploits a pair of security holes -- a format string vulnerability and a heap overflow in the kernel -- to bypass Apple's code-signing requirements and untether devices (see video above).

The jailbreak tool has been released at the greenpois0n and the iPhone Dev Team sites.

Topics: Apple, Mobile OS, Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

21 comments
Log in or register to join the discussion
  • This is news?

    iOS is constantly hacked within minutes. It is a swiss cheese operating system.
    toddybottom
    • so true

      @toddybottom
      November 12 (iOS 5.0.1 release date) was only yesterday, right? Odd how we fit three (or more if you total all population segments) major holidays into the time that it takes to compromise iOS, isn't it?

      This is news, not because it was done, but because there are people who have waited over a month and a half for this who might want to know about it.
      use_what_works_4_U
      • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

        @macadam Its the worst mobile OS (according the zealots) e<br>Everyone should buy a Man-goo phone, as they are the best. The OS is bullet proof and incapable of being hacked. Just be careful of incoming text messages
        ;)
        Rick_Kl
      • It was hacked within minutes

        @macadam
        If you had bothered to read the article:
        "Using a fuzzer, I found after some hours of work that there's a format string vulnerability in the racoon configuration parsing code"

        It took a few minutes.
        toddybottom
      • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

        @macadam Doesn't work on the A5... It still only exploits older products!
        slickjim
      • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

        @toddybottom

        NZ, it appears you didn't read either the article or your own words.

        "...after some [b]hours[/b] of work..."

        "It took a few minutes."
        msalzberg
      • That was a nice try at a defense, did you read what you wrote?

        So it appears that iOS is so secure that it can withstand a few hours of hacking. Way to prove that iOS isn't swiss cheese.

        BTW a few hours is also a few minutes, I never specified a number. No matter how you spin it, iOS 5.0.1 fell extremely quickly. It is a swiss cheese OS.
        toddybottom
      • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

        @NZ

        Nice try, but you still look foolish. Even more so now.
        msalzberg
    • sdfsd

      Coin Bank http://www.chinawholesaletown.com/wholesale-Burlap-Drawstring-Bags/ Consumer Electronics Wholesale Mp3
      Wholesale Glasses http://www.chinawholesaletown.com/wholesale-Octagon-Retractable-Clothesline_112230/ Wholesale Lanyard Wholesale Clocks
      Wholesale Tellurion http://www.chinawholesaletown.com/wholesale-Jewelry-Loupe/ Wholesale Binoculars Silicone Products
      Manicure Set http://www.chinawholesaletown.com/wholesale-Fish-Scale/ Pet Carrier Wholesale Umbrella
      Inflatable Products http://www.chinawholesaletown.com/wholesale-Luggage-Gripper/ Newtons Cradle Promotional Gifts
      Industrial Supplies http://www.chinawholesaletown.com/wholesale-BBQ-Grill/ Sport Support Products Wholesale Speakers
      Wholesale Mouse http://www.chinawholesaletown.com/wholesale-UV-Pen/ Electrical Gifts Wholesale Watch
      Wholesale Golf Products http://www.chinawholesaletown.com/wholesale-Cell-Phone-Cleaner/ Wholesale Badge Wholesale iPod iPhone
      Wholesale First Aid Kit http://www.chinawholesaletown.com/wholesale-Collapsible-Water-Bottle/ Wholesale Gift Bags Wholesale Scissors
      Fleece Blanket http://www.chinawholesaletown.com/wholesale-Badge-Reel/ Wholesale Cap Wholesale Glasses
      Patient Care Products http://www.chinawholesaletown.com/wholesale-Bell/ Spare Tire Cover Solar Products
      Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Leather-Tape-Measure/ Teeth whitening Pen Wholesale Bangle
      Wedding Favors http://www.chinawholesaletown.com/wholesale-Multifunction-Bottle-Opener/ Boomerang Wholesale Stationery
      Crystal Gifts http://www.chinawholesaletown.com/wholesale-Metal-Money-Bank/ Outdoor Leisure Products Ice Players Stick
      Menu Holder http://www.chinawholesaletown.com/wholesale-Wine-Bottle-Cover/ Abacus China Wholesale
      Pet Dog Leash http://www.chinawholesaletown.com/wholesale-Water-Spray-Fan/ Decision Maker Wholesale Compass
      Beauty Equipment http://www.chinawholesaletown.com/wholesale-Washing-Powder/ Wholesale Speakers Men Beauty Care
      Stuffed Animals http://www.chinawholesaletown.com/wholesale-Maracas/ Freezer Mug Wholesale Tie
      Jute Bag http://www.chinawholesaletown.com/wholesale-Tangle-Puzzle/ Wholesale Glasses Wholesale Vase
      Home Appliances http://www.chinawholesaletown.com/wholesale-Leather-Clock/ Wholesale Helmet Wholesale Mat
      Solar Products http://www.chinawholesaletown.com/wholesale-Shaving-Set/ Wholesale Radio Mouse Pad
      Wholesale Mobile Phone http://www.chinawholesaletown.com/wholesale-Whistle-Buckle/ Computer Accessories Wine Set
      Tape Measure http://www.chinawholesaletown.com/wholesale-Tourniquet/ Flash Gift Book Light
      Glass Rimmers http://www.chinawholesaletown.com/wholesale-Poncho-With-Key-Chain-Ball/ Inflatable Products Wholesale Album
      Wholesale Sticker http://www.chinawholesaletown.com/wholesale-Fruitpick/ Automotive Products Promotional Items
      Highlighter http://www.chinawholesaletown.com/wholesale-Beach-Ball/ Wholesale Bracelet Reflective Safety Vest
      jywhy888
  • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

    This is news and now what will happen? Can anyone say?
    leonbakhan
  • Now this is news

    bing: open letter tim cook apple genius

    At least the guy was smart enough to leave BEFORE saying anything that wasn't totally positive about Apple. We all know that you instantly get fired from Apple if you make any comment that can be copied (a judge has ruled on this) and isn't totally positive about Apple.

    I feel very sorry for Apple geniuses, both past and present. They have been used and abused by Apple and some of them right here on ZDNet suffer from serious Stockholm Syndrome. I won't name any names since I don't want to add to their suffering.
    toddybottom
    • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

      @toddybottom I like how your comments get flagged by the Apple zombies - a typical RDF approach. It reminds me the communist propaganda in USSR and North Korea.
      pupkin_z
      • Interesting observation

        @pupkin_z
        I didn't flag him (this time) but do you suppose that the comment might have been flagged as being off topic since it really has nothing to do with the topic of the blog (iOS5 hacking) and is really just another way tor Toddybottom to sadly try and jab at Apple?
        use_what_works_4_U
    • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

      @toddybottom
      I will assume you are talking (at least in part) about me as I have identified myself as a former Apple Genius on numerous occasions. I read the open letter you referenced (an actual link would have been nice 'customer' service but I digress) and I have to say that I agree with the author to an extent. The situation he describes has happened and is happening in some Apple Retail locations, but not all. I know this because I keep in touch with many of my friends who are also former coworkers and we talk about Apple and the stores.

      The management of each individual Apple Store has a lot of influence on the environment within that store. There are stores in my immediate area where this situation has occurred from time to time. Fortunately in this area the situation rarely lasts. I have at times recommended that certain Apple Stores be avoided and others preferred for these reasons, but eventually it levels out. I would also add that the situation is often reflective of the overall talents on a given Genius team. If the team has the experience, knowledge, and maturity to handle their jobs well, they are usually left largely alone to run their shop. If not, then the management is forced to insert themselves into the mix and that's when things can get heavy handed. Unfortunately because this is, after all, a mall job it is often filled by young people with good to excellent technical knowledge but not much real-world experience. You see this a lot after a store has been open for a few years. The initial team members tend to move on to 'bigger and better' things and the vacuum is sometimes filled quickly without the necessary mentoring time for new people. The store I worked in went through this about a year after I left. When the last of the original team had gone, the Genius staff were (for a time) all young and inexperienced. At the same time there was a shift in the management team and the incoming managers just didn't understand how important it is to properly service the customers as opposed to simply selling new product. At that time, I recommended that people use a different location for service needs. Within a few months the team became seasoned again, managers settled down and let the support staff give good support and I am now happy to recommend them to family and friends. If I need technical help I would (currently) be happy to go back there myself, and my measure for satisfaction with Apple service is very high indeed.

      The author is quite correct in that leaving Apple's employ is a bittersweet moment. The demands of offering free retail support are great and it was a relief to leave the crazy schedules and minority of belligerent customers behind. It was also a sadness to leave a company as dynamic as Apple, and the overwhelmingly greater number of customers who were grateful for our assistance. It was truly one of the toughest, most demanding, and most rewarding positions I have ever held and I miss it. The camaraderie in an Apple store is phenomenal as well.

      It's not Stockholm Syndrome, it's the way I still feel about the company after almost 5 years in the corporate environment. Yes, there were bad days, and bad managers, and a lot that could have been better. But the good days outnumbered the bad, and the customers (overall) were some of the best customers a person could ask for. I still miss it to an extent. The greatest rewards come from the greatest challenges, after all.
      use_what_works_4_U
  • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

    As much as it is nice that IOS 5 users now have some degree of freedom, this should not be necessary. Apple really needs to trust their users with their own devices.
    grant@...
    • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

      @grant@... They can't trust their users not to buy movies, music and apps from other sources so that won't work.
      slickjim
      • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

        @Peter Perry

        You forgot to mention the one-button mouse, the lack of right-click, and the DRM on iTunes.
        msalzberg
  • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

    No A5 hack though
    Alan Smithie
    • it's always just a matter of time ;)

      A5 can be jailbreaked and in specific cases even <a href="http://blackbox-iphone.com/index.php/how-does-it-work">unlocked!</a>
      jailbreakandunlock
  • RE: Apple iOS 5.0.1 hacked, untethered via two security holes

    Why should apple be able to dictate to me, what i can and cannot do with my iphone.
    I bought it so its mine!!. Or is it?.
    There are 100s if not 1000s of people out there with useless iphones that have been unwittingly updated by there owners on itunes, thinking they are just updating their ios, but apple doesn't warn them that the baseband will be updated at the same time.
    This renders any software unlock useless.
    That's out of order!!.

    Pablo.
    Pablos234@...