Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it could not "spread itself": it was a browser exploit (although it would be possible to run without the user knowing).

It could certainly spread. Maybe it could SMS a link to a malicious download to your most frequently contacted contacts? Being able to run arbitrary code on a device that knows how to contact all your friends certainly introduces some vectors for attack.



FYI, it is a PDF-based exploit, meaning all users have to do is open a malicious PDF.


It's a font-based exploit, not PDF. The particular implementation on JailbreakMe used a PDF, but it could easily work in @font-face with CSS on any webpage (or, as we did on JailbreakMe, just hiding an <iframe> to the PDF).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: