also @ TechSpot: Intel says Haswell will improve battery life by 50 percent

iOS 4.1 security hole allows using the iPhone when it's locked

By Emil Protalinski

On October 26, 2010, 2:21 PM

With the latest iOS 4.1, it appears that Apple has opened up a small security vulnerability: the iPhone's passcode no longer works as it should. If you input a random number in the emergency call field, press call, and then promptly hit the hardware lock button, you will gain access to the Phone app. The issue occurs on all iPhones that can been upgraded to iOS 4.1; the iPhone 3G, iPhone 3GS, and iPhone 4 are all vulnerable.

In other words, even if your phone is locked, you can make non-emergency phone calls from it. This could be easily abused by thieves who use your phone to make expensive calls right after they steal your iPhone. The hole also grants the user access to favorites, contacts, recent calls, and voicemail. Additionally, selecting "share contact" and then the camera icon will give you access to the photo album. Furthermore, if the user holds down the menu button he or she can gain access voice control and play locally-stored music. Here's a video from Boy Genius Report showing the issue:

We expect that Apple will have a fix available by iOS 4.2, though there's no date for that release yet. Currently, the 4.2 beta still has this problem since it has only been recently discovered and sent as a bug report to Apple.


,

User Comments: 27

Got something to say? Post a comment
  1. HAHA, most of your comments make me laugh... Beating on crApple is fun!!

    Also, don't forget they made a tablet with wifi issues and blamed the consumer's routers.

    I honestly wouldn't pick on Apple so much if they weren't so stuck up about how perfect their products are. So I can't help but laugh at their misfortunes.

    That's exactly how I view it, if Apple didn't have their "holier than thou" attitude then I probably wouldn't care, but they do, so I love reading stuff like this. It sucks for the consumer though, they're the ones who pay... but then again, most of them don't seem to mind... maybe most of them like technological submission/sadism?

  2. Why can't they just release a hotfix like 4.1.1 or something instead of waiting until 4.2 is ready?

    Actually, I can (shh) run i O S 4 . 2 on my iPad, and I'm not a dev.

Recently commented stories

Post a new comment

Social Login & Guest Posting TechSpot Members
Login here or sign up for free,
it takes about a minute.
Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.
TechSpot on:

Subscribe to TechSpot

Get free exclusive content, learn about new features and breaking tech news.