iPhone SMS Vulnerability Patched With OS 3.0.1
We made several cautionary posts about the iPhone’s SMS vulnerability over the past month, and it’s finally getting a fix. iPhone OS 3.0.1 is out today at a whopping 280MB.
Apple was apparently highly pleased with themselves for the fix:
We appreciate the information provided to us about SMS vulnerabilities which affect several mobile phone platforms. This morning, less than 24 hours after a demonstration of this exploit, we’ve issued a free software update that eliminates the vulnerability from the iPhone. Contrary to what’s been reported, no one has been able to take control of the iPhone to gain access to personal information using this exploit.
Nice to hear that no one has actually used the exploit to devious ends, but “less than 24 hours after a demonstration of this exploit” is Bushian in its absurdity. The two dates, the update release and the demonstration, are pretty clearly unrelated. It’s not like Apple just threw this thing together over the last 24 hours. If they had, I probably wouldn’t bother installing it. They’ve known about the problem for at least a month. I know that because I’ve known about the problem for a month.
Here’s to completely arbitrary horn-tooting!