Apple improves security in iPhone 2.1

Among the many improvements to the iPhone with the 2.1 software update posted on Friday are changes meant to enhance security on the device. Apple has provided details about what’s changed. All of the changes affect security issues noted for iPhone 2.0 through 2.0.2 software releases. None of the problems affect iPhone software prior to 2.0.

Among the notable fixes in 2.1:

  • an update to the Application Sandbox to enforce proper access restrictions.
  • FreeType vulnerabilities have been shored up.
  • mDNSResponder has been updated to reduce susceptibility to DNS cache poisoning.
  • TCP initial sequence numbers are now randomly generated to stop attackers from spoofing TCP connections.
  • Passcode Lock has been corrected to fix the emergency call exploit.
  • WebKit has been updated to address CSS import statements that were causing problems.

Leave a Reply