
Last Friday, Apple released an update to its PDF reader, patching the flaw exploited by JailbreakMe 3.0. This is the second jailbreak-related PDF vulnerability that Apple has been forced to address. Apple stated that “viewing a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary code execution” and that it is “available for iOS 3.0 through 4.3.3 for iPhone 3GS and iPhone 4 (GSM model), iOS 3.1 through 4.3.3 for iPod touch (3rd generation) and later, iOS 3.2 through 4.3.3 for iPad”.
However, comex already released a patch for jailbroken iDevices, called PDF Patcher 2. Already jailbroken users are advised by the iPhone Dev Team to install PDF Patcher 2 so that they may be protected from security vulnerabilities, and it works for any firmware version. (Instructions: load Cydia, search for PDF Patcher 2, tap INSTALL and CONFIRM.)
Many publications have reported that 4.3.4 is already jailbroken. To be more precise, although users can install a jailbroken version of iOS 4.3.4 on certain devices, those jailbreaks rely on vulnerabilities present in the hardware of certain devices. This is independent of the iOS version it is running on, and hence will not work on all iOS 4.3.4 devices. These jailbreaks often will require a special program to be used every time the device needs to be booted up (i.e. a “tethered” jailbreak).
For the iPad 2, no such hardware vulnerability has yet been discovered, so iOS 4.3.4 cannot be jailbroken at all for that device.