Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Applications
    • Applications
    • Cybersecurity
    • Development
    • Mobile

    Apple Fixes Battery, Kernel Issues in iOS 5.0.1 Update

    Written by

    Fahmida Y. Rashid
    Published November 11, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Earlier this week, a security researcher well-known for hacking Apple products said he’d found a kernel bug that let him run unsigned code on iOS devices, bypassing Apple’s protections. Within 72 hours, Apple has fixed that flaw.

      Apple released an update to iOS 5 on Nov. 10 for the iPhone, iPod Touch, and iPad to fix a bug that caused the battery to drain and a handful of security bugs, including the flaw discovered by Charlie Miller, a principal research consultant at Accuvant. This would be the first time Apple would distribute an iOS update over the air, so users don’t have to connect directly to a computer to install the patches.

      Miller discovered a bug in the iOS kernel which would allow a malicious developer to run unsigned code on the user’s iPhone or iPad. He exploited the bug by creating an app which would phone home to a server and open a remote shell. Miller was able to issue remote commands and perform several tasks on the device. When reports of the exploit were publicized, Apple yanked the app off the iTunes App Store and suspended Miller from the developer program.

      “It’s obvious that Charlie Miller really got under the Apple skin. This must be some kind of record; Apple ousted him from the developer program and then patched his bug in record time,” Andrew Storms told eWEEK.

      Even knowing how quickly Apple can patch serious security flaws, the turnaround was “surprising,” Storms said. The company had to address this problem immediately because it “struck a serious blow at the ‘halo of safety'” that surrounded the iTunes App Store, according to Storms.

      The bug, and the fact that Miller was able to get an app past Apple’s review process and into the App Store, showed the platform wasn’t immune to some of the problems Google has had with malicious apps appearing on the Android Market. The fact that Apple reviewed each app was supposed to prevent dangerous apps from slipping in.

      “Charlie’s critical flaw definitely has the potential to eat away at the trust Apple has carefully developed with users, partners and developers,” Storms said.

      The battery problem was one of the first problems uncovered after Apple released iOS 5 in October. Almost immediately, users complained about the battery life plummeting after upgrading their devices to Apple. The company maintained its silence during the entire time users were complaining, before acknowledging “a software problem” and promising a patch. In the advisory, Apple did not give any details. “Fixes bugs affecting battery life,” the company said in the advisory.

      Apple also fixed two security flaws, discovered by Facebook’s Erling Ellingsen, which could have disclosed personal data on iOS devices if the user had visited a malicious Website, the advisory said. The issue in CFNetwork could be exploited through a maliciously crafted URL, causing CFNetwork to navigate to an incorrect server, according to the advisory. The other issue was in libinfo and how it handled Domain Name Server (DNS) lookups and could have been exploited with a maliciously crafted hostname, Apple said.

      The CoreGraphics bug exposed users to arbitrary code execution if they viewed a document containing a maliciously crafted font. The flaw involved multiple memory corruption issues in FreeType, according to Apple. The company also revoked DigiCert Malaysia certificates after recent reports that the certificate authority had been compromised.

      Apple also fixed a problem with Passcode Lock which allowed a person with physical access to a locked iPad 2 to still be able to access user data. “When a Smart Cover is opened while iPad 2 is confirming power off in the locked state, the iPad does not request a passcode,” Apple said.

      Apple also fixed problems with documents stored in iCloud, improved voice recognition capabilities for users with Australian accents and added multi-tasking gestures to the original iPad.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.