iPhone OS 3.0.1 update released, fixes SMS vulnerability (updated with statement from Apple)
Looks like Apple pulled the trigger on patching that nasty iPhone SMS vulnerability a little earlier than we expected -- the iPhone OS 3.0.1 update just hit iTunes. It's not some lightweight, either: you're looking at 280MB of love here, so get downloading, friends.
Update: Here's what Apple rep Tom Neumayr had to say about this little episode.
[Thanks to everyone who sent this in]
Update: Here's what Apple rep Tom Neumayr had to say about this little episode.
Well... what do you know about that?We appreciate the information provided to us about SMS vulnerabilities which affect several mobile phone platforms. This morning, less than 24 hours after a demonstration of this exploit, we've issued a free software update that eliminates the vulnerability from the iPhone. Contrary to what's been reported, no one has been able to take control of the iPhone to gain access to personal information using this exploit.
[Thanks to everyone who sent this in]

















hmm think ill just wait until 3.1 before I have to re-jailbreak
I concur. Not loosin' slingbox over 3G for this ;)
Also nice going Apple making people download the whole 300mb iPhone OS again for a .01 upgrade instead of a 50kb patch.
But what if someone sends you an SMS that makes your jailbroken iphone take down the entire cellular network?
AT&T Customers would probably cheer!
...and itunes/pre syncing? :)
@ OneLove
This is an iPhone update, not an iTunes update.
How on earth can an update patch to a newly released massive update to the O/S be 280mb?!?!?
That's some pretty shocking bloat.
It's because Apple makes you download the whole firmware image instead of just a simple patch.
@Ernesttechuser - And people make fun of Microsoft bloat. Holy crap, Apple
@Ernest: That's how Apple does it. Every other company has figured out how to do incremental updates, but Apple still can't seem to, and instead they make you download the entire software/OS (they do the same for iTunes updates as well)
I'm trying to figure out why the update firmware is 17MB less than the original 3.0, unless that 280MB quote was only for the 3g and not the 3gs.
Cancel that, Jim on the next page answered my question "297.9 Mb in my case".
^ Not developers ^
My bad, Reading fail, etc. (...and it's Friday)
Apple used to do delta updates for the iPhone 2 years ago. The only reason I can think that they stopped doing them is due to the problems they had when applied to a jailbroken device.
Why does file size matter? Are you guys downloading the update over dial-up?
@ Jeff
they can't find anything else to complain about.
lol you gotta love that statement ... apple just had to stress that its a "free" update ... lol good thing the ipod cant text message or you would have to pay $5 to get a security patch.
Beside the benefit of not needing to install 10 little patches to update your whatever if it goes splat I find it pretty freakin tedious that a patch needs the whole mushy mess just to tweak a line if code.
How's about a half way option where it downloads the patch into the image stashed in iTunes and then reloads the updated image.
Mine was only 230.1 MB
mine 228mb
@ Cy:
Because there's nothing tedious about a 5-minute download. I'd imagine just about everyone who can afford a monthly iPhone data plan can afford (and has) broadband web access.
does anybody see any issues? my iPhone behaves kinda funny after the patch. Basically when I turn it on nothing happens, I have to click the big button 2x
it's really weird and really really annoying
@d889 - Apple don't make you pay for point upgrades on the Touch, only major revisions. So any security patch for the iPod Touch would be free.
Why don't all you complainers just go to apple and give back the phone and shut the he'll up . You sound stupid. You complain about an update that takes a few mins. no matter how apple wants to do it why do you care. Yet here you are using the iPhone. You guys are probably the same ones still living in moms basement and using her phone service.
lol at the jailbreakers
LOL at the tools like you!
Jailbreaking is great for Apple... that means more iPhones in the wild. Plus "LOL AT&T USERS" is required here.
Why LOL at Jailbreakers, they are the ones inovating for the IPhone, Apple has fallen behind someone has to pick up the slack. Not to mention their horrible App store policies preventing perfectly good apps on there like the original slingbox app over 3G, google voice app, those types of things! Maybe if Apple and AT&T didn't suck so much in that respect people wouldn't have to jailbreak. It's more like LOL at you for not fully utilizing your iPhone.
@ Kanos :: He probably doesn't even have one.
My Tron theme laughs at your un-jailbroken phone: http://www.modmyi.com/forums/new-skins-themes-launches/678618-tron-v1-1-release.html
The problem with themes is that you'll always have an app that sticks out like a sore thumb.
@TREX6662k5: you can always just make your own icon to match the skin, most skins also provide a psd for the basic icon stucture/design so that you can make your own
That's why I just get my page 1 set with all the "themed" icons, and leave the other pages with their defaults. Keeps it simple (so I don't go crazy finding icons for every app) and leaves things like games with their original artwork.
@Jahooba - haha that is some ugly ass shit
@TREX6662k5: this is quite true.. it annoyed me as well but i used a theme i found at http://iphonethemes.net that skins the icons it self.. something to do with overlay.. idk but it was cool.. have to put it again after jailbreaking this new update
- Yunus
3.0.1 can be jailbroken, just FYI. You're an idiot for laughing out of ignorance..
Breaking news for a 0.0.1 update! This must be Engadget!
Yeah, it's not like the SMS vulnerability was a hot topic or anything.
It was a "top story" on BBC's website yesterday :P
Awesome! Hello thar panic reaction!
Tell me, Mr. Anderson... what good is a phone call... if you're unable to speak?
Let's not make fun of the verbally challenged.
@ professorDex
matrix reference.
@ mike - he probably knew that. Sarcasm++
wow at "Mr Anderson",, you so reminded me of the Matrix hehe
MSM: I believe -that- was the point?
There is no spoon.
There is however a month of non activity then a frantic rush to get a patch out the door.
"There is however a month of non activity then a frantic rush to get a patch out the door."
I don't think so. I'm sure it was being addressed the moment they were notified, "Months ago," as Charlie Miller stated. I theorize that Apple waited until after yesterday's announcements at Black Hat to make the patch available, in case there was some new angle that Miller added in late in the game yesterday that might have to be patched again, days later.
Either way, it's been addressed, to the dismay of Apple haters everywhere!
Does it break teathering?
except for the fact that engadget is covering this due to the controversy surrounding Apple initially choosing to ignore the huge security flaw while its competitors have already addressed and fixed the issue, who only bit the bullet because it was publicly demonstrated. Apple doesn't want any more negative press than they are already getting these past couple of weeks. Get off of Engadget's nuts.
'Phones incorporating the Windows Mobile and Google Android operating systems are also vulnerable, they said.'
http://news.bbc.co.uk/2/hi/technology/8177755.stm
Real haters don't let facts get in their way.
@why not the LS2LS7?: I'm guessing you're implying he was wrong in saying Android/Windows Mobile fixed the issue? I don't know about Windows Mobile but from that same article you linked to: "Google said that it had already patched the weakness".
@why not the LS2LS7? - Did you not read where he said competitors already fixed their OS's? Sure WinMo and Android are vulnerable - if they didn't update! The same hold true for all OSs.
@mark so far only google and apple have applied a fix. Im sure winmo will get one in Windows Phone 7
One of the reasons Apple probably waited so long was so they could be like "Look everyone! We're the only company that fixes a security hole in less than 24 hours!!" when in reality, it's been fixed for a while.
Way to put your users at risk, Apple. Not everyone applies the security update the instant it is released.
I have an HTC Touch, and I honestly can't remember the last time I've gotten an update for my phone. Actually, wait, I do, it was the 6.1 update I got about a year ago. I love that the over the air update function never actually works...
I'm waiting until a 3.1 jailbreak. If Apple makes it so that you need 3.0.1 to download from the App Store like they did with 3.0, it's gonna suck.
Does anybody else find it strange that the itunes logo has a CD in it but that almost no one uses itunes to rip CDs? If anyone can be blamed for the downfall of CD sales it is itunes, but there it is, right in their logo. Just a random observation...
Nice observation
I'm guessing it's there for nostalgic purposes.
Could now be considered a DVD which is symbolic of the fact that iTunes does more than just music.
If you look at the full sized icon, the cd says iTunes 7 .. and Apple 2006 on the lower half of the inner circle :>
Its more interesting since iTunes hasn't been on a CD since .. what . . version 4? Its been a while . . .
Kinda like the floppy disk icon we use to save?
Maybe it's a laserdisc.
I know plenty of people who used iTunes to rip all their old CDs.
Most don't buy CD's anymore, but that a different story...
The disk with the blue note symbol on it.... Apple's support for Blu-Ray is finally coming?
I certainly will not be updating as the update is likely to fix the tethering hack.
3.0.1 does not disable the tethering hack
someone needs to confirm this.
Confirmed. Tethering still works after the 3.0.1 update.
Confirmed
I just downgraded my iPhone 3G from 3.0 to 2.2.1 last night. I couldn't take the awful battery life, hot phone, and extremely poor performance. I don't be upgrading to 3.x until they fix their bugs. (Of course, it could be intentional, to make the iPhone 3G seem slow and out of date.)
Er, that should be "won't be"
I've been thinking the same thing with how slow the 3.0 package is.
If you're looking to downgrade, you have to be brave. I had to try a dozen times (no joke), and kept getting error messages. The best way seemed to be to click restore and let it put 3.0 on again, get 2.2.1 as an ipsw, use quickpwn, attempt to downgrade with the custom ipsw in iTunes, and THEN do it all over again. There were moments when I thought I had a bricked phone (didn't turn on, wasn't in DFU mode).
Good lord really? I've got an Iphone 2 weeks ago, updated to 3.0 the first day. Is it suppose to be slower?? I feel its fast ok and I can watch 4 movies and still have some power.
I had major battery issues with my unlocked original iphone. A simple restore with the exact same custom firmware as before fixed the issues. No idea why. My battery can last 4-5 days now instead of 2-3 that i was getting with 2.x and
rather wait for the 3.1 update and then re-jailbreak later, no use in download a .01 update,
Hey wasn't other smart phones vulnerable, did they get an update..............
Hey yall geeks really need to chill, yall be getting mad at each other for silly things trying to prove who's smarter, look at all the assholes making the internet a bad place, unite and solve common problems.
But yall still going come here bash Apple, Sony, Microsoft, each other and praise Linux. Geeks
Can't we all just get along and not like Linux?
I agree that we should all get along, but the reality of life is that it will never happen. Now what was I saying about rednecks who have terrible grammar, can't spell, and use the word yall (sic) all the time? Oh yeah, they can suck it.
Now, isn't that better?
Anyone have a direct link to the software ipsw?
iPhone: http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6974.20090731.Cf4Tg/iPhone1,1_3.0.1_7A400_Restore.ipsw
iPhone 3G: http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6972.20090731.Zx3Rr/iPhone1,2_3.0.1_7A400_Restore.ipsw
iPhone 3GS: http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-6976.20090731.Vgbt5/iPhone2,1_3.0.1_7A400_Restore.ipsw
Thanks a ton!
iPod Touch?
@Keith
I don't think their is any need for a Touch update. As this only fixes the SMS vulnerability.
i wonder what mr.chapel have to say about this?
Who cares! Don't encourage him!
He doesn't own an iphone, but that's never stopped him before.
I most definately will NOT be updating to 3.0.1. Apple are likely to have fixed the tethering hack. I cant live without this feature and I have no desire to pay o2 £15 per month for the tethering bolt on given that they have been fleecing me for many years
I think I'll wait to see if a patch gets released on Cydia... Apparently Chronic Dev Team are working on one. It'd save me having to mess about restoring my iPhone
Does anyone know if 3.1 breaks the 3.0 tethering hack?
*3.01
wondering same. someone will have to download and test!
There's no indication that the update does anything but fix the SMS vulnerability. It's a huge update though..... 297.9 Mb in my case. The bit comparisons should reveal what, if anything else, might have changed.
Apple releases full versions of the firmware after updating them instead of just patches. Stupid we know but also the reason for the large file sizes.
Amazing how many people on Engadget own iPhones...from all the pro Microsoft, Rim, Nokia, Palm posts, not to mention the Apple bashing posts, you would think there aren't any Apple fans on this site...
I guess Apple did sell some iPhones...of course, everyone on this site won't be upgrading because they hate their iPhone or have jailbroken it because they hate AT&T or Apple's iron fist...lol you guys crack me up.
Didn't you know? It's trendy to be hypocritical in today's society.