Hacker finds iOS 4.1 bootrom vulnerability


Recommended Posts

Hacker finds iOS 4.1 bootrom vulnerability that can jailbreak all current hardware

http://www.geek.com/articles/apple/hacker-finds-ios-4-1-bootrom-vulnerability-that-can-jailbreak-all-current-hardware-2010099/

Yesterday?s release of iOS 4.1 was good news for iPhone gamers and iPhone 3G owners who had performance issues post-4.0, but bad news for jailbreakers, with the Dev Team themselves warning users not to upgrade to 4.1 as there was no known way to reverse the baseband post-update.

As usual, though, what?s true in the cat-and-mouse jailbreaking scene one day is not true the other, and now there?s good news for jailbreakers, at least in theory. iPhone hacker pod2g has revealed on Twitter that he has successfully discovered a new bootrom exploit, and even better: all the new iOS hardware including the iPhone 4 and new iPod Touch is vulnerable to it.

The good news here is that means that Apple would be powerless to patch this vulnerability through software, since its a hardware issue? but that won?t necessarily stop them from patching up the issue at the factory for any hardware that comes down the line in coming months.

So, in theory, the Dev Team should be able to use this to jailbreak any iPod Touches and iPhone 4s currently in the wild? but given Apple?s historic response to jailbreaking, don?t expect this vulnerability to last. If you want a new iPod Touch or iPhone 4, and if you want to jailbreak it, buy your device now? if you buy it in a few months, you may very well be out of luck.

Hacker finds iOS 4.1 bootrom vulnerability that can jailbreak all current hardware

http://www.geek.com/articles/apple/hacker-finds-ios-4-1-bootrom-vulnerability-that-can-jailbreak-all-current-hardware-2010099/

Yesterday?s release of iOS 4.1 was good news for iPhone gamers and iPhone 3G owners who had performance issues post-4.0, but bad news for jailbreakers, with the Dev Team themselves warning users not to upgrade to 4.1 as there was no known way to reverse the baseband post-update.

As usual, though, what?s true in the cat-and-mouse jailbreaking scene one day is not true the other, and now there?s good news for jailbreakers, at least in theory. iPhone hacker pod2g has revealed on Twitter that he has successfully discovered a new bootrom exploit, and even better: all the new iOS hardware including the iPhone 4 and new iPod Touch is vulnerable to it.

The good news here is that means that Apple would be powerless to patch this vulnerability through software, since its a hardware issue? but that won?t necessarily stop them from patching up the issue at the factory for any hardware that comes down the line in coming months.

So, in theory, the Dev Team should be able to use this to jailbreak any iPod Touches and iPhone 4s currently in the wild? but given Apple?s historic response to jailbreaking, don?t expect this vulnerability to last. If you want a new iPod Touch or iPhone 4, and if you want to jailbreak it, buy your device now? if you buy it in a few months, you may very well be out of luck.

I believe there is also a known vulnrability in the iOS itself which will allow for a type of usenet jailbreak similar to the jailbreak.me site? Although this could\would be patched by a software update, for now, it would be great if someone would release a jailbreak using this method until the bootrom exploit is configured correctly.

I know the current JBs for 4.0.2 work in 4.1, but result in the phone app missing, but im thinking of running the JB and fixing the app myself, until an official JB is released in the comeing days.

No point in having more than one exploit out in the wild since Apple will just patch it and then when the next version comes out it can't be used. :p

Urm, but why not use the current software exploit to create a usenet jailbreak, whilst the bootrom JB is being created. After that Apple can patch the software exploit all they want.

Its funny how companies put sooo much money in to protecting their products and before or soon after some is released, it gets hacked. They cannot win so why do they bother.

To make it difficult :)

If enough users did it, and they could do it with the simple download of one application for all firmware releases, it would be a lot more common. As it is many users stay away because they fear bricking their phones, they don't understand what firmware version they have or what program to use to do it. Or they've just never thought of the benefits and label it as "something geeks do".

IMHO apple have had reasonable success keeping people from doing this, I know plenty of people who refuse to jailbreak pretty much solely for the above reasons.

Its funny how companies put sooo much money in to protecting their products and before or soon after some is released, it gets hacked. They cannot win so why do they bother.

first, i am assuming you are referring to Apple since this is an iOS thread.

Apple should just give up because people found and took advantage of a hole in the iPhone/iPad/iPod Touch?

Apple is a publicity traded company worth billions of dollars, there's a clear and obvious reason they continue to patch the software, not to mention the number of people that would out of work if they were no longer writing and fixing the software

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Exactly. They won't go 100 because current gen consoles are simply too old for any groundbreaking graphics or gaming experience otherwise. They will go with standard (console) price 70 or go with 80 if they really want to go premium. Of course they will have more expensive options too with some useless cosmetics as always.
    • Doesn’t surprise me at all. God is light & He gave us life so it sounds almost logical that we would therefore emit a certain amount of light.
    • This is what I want. Hey Gemini, how do I remove you from all my google products permanently?
    • I would never install install this build before rtm process. only 3 months to go. never install on your daily devices. just wait 3 months.
    • Motrix Next 3.9.6 by Razvan Serea Motrix Next is a modern, open-source cross-platform download manager built as the official next-generation successor to the original Motrix project. It has been completely rewritten using Tauri 2, Vue 3, TypeScript, and Rust, while still relying on the powerful Aria2 download engine for high-speed multi-protocol transfers. The app supports HTTP, HTTPS, FTP, BitTorrent, ED2K and magnet links, offering advanced features like multi-connection acceleration, task scheduling, bandwidth control, and batch download management. With a significantly reduced install size (around 20MB), it focuses on being lightweight, fast, and resource-efficient compared to traditional Electron-based download tools. Designed for Windows, macOS, and Linux, Motrix Next delivers a clean, modern UI inspired by Material Design 3 principles, with smooth animations and a minimal workflow. It improves usability through better download organization, system tray integration, and enhanced torrent handling including selective file downloads and tracker management. Motrix Next features: Multi-protocol downloads — HTTP, FTP, BitTorrent, Magnet, .torrent, ED2K, and Metalink tasks BitTorrent — Selective file download, DHT, peer exchange, encryption controls, metadata caching, GeoIP peer flags, and tracker probing Browser extension integration — Embedded Extension API with independent authentication, download confirmation, smart auto-submit, filename hints, referer/cookie forwarding, and real-time controls (Chrome Web Store · Edge Add-ons) Safe filename handling — Content-Disposition, RFC 2047, non-UTF-8, percent-encoded, and extensionless URL resolution with path traversal sanitization Download organization — Favorite and recent folders, optional file-type categorization, stale-record cleanup, and completed history backed by SQLite Concurrent downloads — Independent controls for active tasks, HTTP connections per server, segments per file, and BT peer limits Speed control — Global and per-task upload/download limits with day-of-week and time-of-day scheduling System integration — Tray operation, optional tray speed display, macOS Dock badge/progress, protocol handlers for magnet://, thunder://, and motrixnext:// Lightweight mode — Destroys the WebView on minimize-to-tray while Rust keeps the engine, task monitor, notifications, history, and extension routing alive Notifications and power options — Native task start/complete/failure notifications, keep-awake during downloads, and optional shutdown after completion Network controls — Scoped proxy support for downloads, app updates, and tracker updates, plus system proxy detection Auto-update channels — Stable, Beta, and Latest Across Channels policies with separate download and install phases Diagnostics — Structured logs, exportable diagnostic ZIPs, database integrity checks, automatic DB rebuild, and Linux GPU rendering fallback Personalization — Light/dark/system theme, 10 color schemes, 26 languages, and first-launch system language detection Motrix Next 3.9.6 changelog: New Features Clipboard management — App-owned copy actions no longer trigger the Add Task auto-detect popup. aria2 input compatibility — Multi-line aria2-style task input is supported for URLs with per-task options such as out=. BitTorrent IPv6 DHT — Added IPv6 DHT support and related configuration. File category URL patterns — File category rules can match URL patterns with validation and localized hints. Task status tags — Added clearer waiting and sharing states for task cards. Download event bridge — Added an aria2 WebSocket event bridge for faster download notifications. Improvements Improved task list transitions and preserved task state during tab switches. Kept RPC origin access enabled for local integrations. Restored AppImage stripping in release builds after beta validation. Added localized preference guidance across supported languages. Download: Motrix Next 64-bit | ARM64 | macOS ~20.0 MB (Open Source) Links: Website | macOS / Linux | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      508
    2. 2
      +Edouard
      181
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      75
  • Tell a friend

    Love Neowin? Tell a friend!