Apple: The leaked iPhone Source Code is Outdated
Apple has responded to security concerns surrounding leaked iPhone source code, pointing out that any potential vulnerabilities would be outdated.
"Old source code from three years ago appears to have been leaked," Apple said in a statement, "but by design the security of our products doesn't depend on the secrecy of our source code. There are many layers of hardware and software protections built in to our products, and we always encourage customers to update to the newest software releases to benefit from the latest protections."
The iBoot source code for iOS 9, a core part of what keeps your iPhones and iPads secure when they turn on, was leaked on GitHub, Motherboard first reported. iBoot essentially makes sure all software that loads on Apple's devices is secure and hasn't been tampered with.
Because iBoot is such a crucial part of an iOS device's security, Apple offers its bug bounty program's highest reward -- $200,000 -- to anyone who can find vulnerabilities in the code.
The source code leak was considered a major security issue for Apple, as hackers could dig through it and search for any vulnerabilities in iBoot. Apple had used a DMCA notice to get the Github page hosting the leaked code taken down, but multiple copies of the code have already spread online.
The leaked source code from iOS 9 was first released in 2015. Only 7 percent of iOS devices are running a version older than iOS 10, which came out in September 2016, according to Apple.
"The iBoot code that was leaked is for an older iOS, so whatever bugs people find may not be relevant anymore," said Michael Borohovski, co-founder of Tinfoil Security.
But with more than 1 billion iOS devices in the world since 2016, that's still at least 70 million people who could be affected by any new vulnerabilities that could spring up.
"There's a wide range of things, from new jailbreaks to the possibility of circumventing Apple's process, based on having access to the source code," said David Kennedy, the CEO of security company TrustedSec.
- UniBoot -- a Semi Untether for iOS 9.x - 10.x iOS9.3 Beta 4 and New iOS 9.2.1 Have Been Supported by 3uTools iOS 9.2.1 Has Been Jailbroken Successfully by Luca Todesco Tihmstar Launches JailbreakMe 4.0 for 32-bit iOS 9.1-9.3.4 Devices Apple Released the Final version of iOS 9.2.1 iOS9.3 Is Coming Soon, and Will You Wait for iOS 9.2 Jailbreak? Apple Reopens Some Older iOS Versions After Closing iOS 9.3.5 [Update] You Need to Know These Things before Upgarding iOS 9.2