Ride the Lightning

Cybersecurity and Future of Law Practice Blog
by Sharon D. Nelson Esq., President of Sensei Enterprises, Inc.

Hackers Release iPhone Jailbreak Tool for Almost all iPhones

March 3, 2021

Yahoo Finance reported on March 1 that an iPhone hacking team has released a new jailbreak tool for almost every iPhone, including the most recent models, by using the same vulnerability that Apple last month said was under active attack by hackers.

The Unc0ver team released its latest jailbreak and says it works on iOS 11 (iPhone 5s and later) to iOS 14.3, which Apple released in December.

For those who do not know, jailbreaking is sort of a cat-and-mouse game between security researchers who want greater control and customizations over their phones, and Apple, which locks down iPhones for security reasons. Hackers build jailbreak tools by finding and exploiting vulnerabilities that can remove some of the restrictions that Apple puts in place, like installing apps outside of its app store, which many Android users do.

The jailbreak group said in a tweet that it used its “own exploit” for CVE-2021-1782, a kernel vulnerability that Apple said was one of three flaws that “may have been actively exploited” by hackers. By targeting the kernel, the hackers can get deep hooks into the underlying operating system.

Apple fixed the vulnerability in iOS 14.4, released last month, which also prevents the jailbreak from working on later versions. It was a strikingly rare admission that the iPhone was under active attack by hackers, but the company declined to say who the hackers were and who they were targeting. Apple also granted anonymity to the researcher who submitted the bug.

The group’s last jailbreak, which supported iPhones running iOS 11 to iOS 13.5, was fixed in a few days last year. Apple works doggedly to fix the vulnerabilities found by jailbreak groups because these vulnerabilities can be exploited maliciously.

Security experts regularly advise iPhone users against jailbreaking because it makes the device more vulnerable to attacks. While keeping your phone up to date may introduce security fixes that remove the jailbreak, it’s one of the best ways of keeping your device secure.

What users want vs. security is a never-ending battle.

HT to Dave Ries.

Sharon D. Nelson, Esq., PresidentSensei Enterprises, Inc.
3975 University Drive, Suite 225|Fairfax, VA 22030
Email:  Phone: 703-359-0700
Digital Forensics/Cybersecurity/Information Technology
https://senseient.com
https://twitter.com/sharonnelsonesq
https://www.linkedin.com/in/sharondnelson
https://amazon.com/author/sharonnelson