Apple Confirms iPhone Source Code Leak is Real, But Says its Security Doesn't Depend on Secrecy

Source code for iBoot, a core component of the iPhone's operating system leaked on GitHub yesterday, raising concerns that the hackers and security researchers could dig into the code to find iOS vulnerabilities.

iphone se ipad deals
In a statement issued to MacRumors this morning, Apple confirmed the authenticity of the code but emphasized that it's for iOS 9, a three-year-old operating system that's been replaced with iOS 11 and is in use on only a small number of devices.

"Old source code from three years ago appears to have been leaked, but by design the security of our products doesn't depend on the secrecy of our source code. There are many layers of hardware and software protections built into our products, and we always encourage customers to update to the newest software releases to benefit from the latest protections."

Based on data from Apple's App Store support page for developers, iOS 11 is installed on 65 percent of devices, iOS 10 is installed on 28 percent of devices, and earlier versions of iOS, such as iOS 9, are installed on just seven percent of devices.

In addition to acknowledging that the leak contained real source code, Apple this morning also sent a DMCA takedown notice to GitHub this morning, successfully getting the code removed from the site.

The data that was shared on GitHub was incomplete so the iBoot code was not able to be compiled, but it did include a documents directory that offered up additional information relevant to iBoot, and combined, the data leak could make it easier to locate vulnerabilities to create new jailbreaks.

Average users should not need to be concerned about the leak, however, as Apple has many layers of protection in place, like the Secure Enclave, and does not rely on source code secrecy alone as a way to keep its users safe.

Security researcher Will Strafach, who spoke to TechCrunch, echoed what Apple had to say. He believes the source code is compelling because it provides an inside look into the inner workings of the bootloader, but ultimately, "Apple does not use security through obscurity," so there is nothing risky in the code.

Top Rated Comments

Norbs12 Avatar
42 months ago
"root" <enter> <enter>

jk jk

Glad they are actually being vocal instead of almost dead silent during the battery thing. That just lead to people coming to their own conclusions. It's quite a bit harder to change people's minds once they form their own opinion, even if it's dead wrong.
Score: 15 Votes (Like | Disagree)
scrapesleon Avatar
42 months ago
this transparency thing getting out of hand
Score: 8 Votes (Like | Disagree)
keysofanxiety Avatar
42 months ago
How many of the "better post quick and say something sarcastic" posters actually read the article and saw it was for iOS 9?
Score: 8 Votes (Like | Disagree)
OldSchoolMacGuy Avatar
42 months ago
Anyone could always just decompile the code. C doesn't decompile as easily/neatly as, say, java, but products like Hopper Decompiler exist if you want to convert from compiled code to C.
HA! Good luck with that. Give it a try and let us know how it works out. Hint: there's a reason someone hasn't just done that.
[doublepost=1518120690][/doublepost]
"we always encourage customers to update to the newest software releases to benefit from the latest protections"

...and for those of you with older devices that cannot run the newest software releases, we encourage you to throw your device into a landfill because the millisecond that we make a new iOS version, we stop putting security fixes into the previous version.
That's not true at all. Apple continues issuing security updates for older devices years after they're no longer on sale. Android has new devices on the market which don't even run the current version of Android. The same can't be said for their push to secure older devices like Apple.
Score: 7 Votes (Like | Disagree)
Rshill Avatar
42 months ago
Not so worried about the security implications, but it could mean that ios could be booted on a generic ARM device. Basically a "hackintosh" for ios.
Score: 7 Votes (Like | Disagree)
AJ5790 Avatar
42 months ago
It’s pretty funny that, ever since Tim Cook said Apple was doubling down, they’ve surely had twice as many fails.
And they’re like 200% bigger. Funny how that works.
Score: 7 Votes (Like | Disagree)

Top Stories

samsung experience 1

Samsung's 'iTest' Lets You Try a Galaxy Device on Your iPhone

Thursday April 8, 2021 12:42 pm PDT by
Samsung has launched "iTest," an interactive website experience that's designed to allow iPhone users to test out Android on a Galaxy device, or "sample the other side," as Samsung puts it. Subscribe to the MacRumors YouTube channel for more videos. The iTest website is being advertised in New Zealand, according to a MacRumors reader who came across the feature. Visiting the iTest website on...
pixel watch prosser leak

Google Pixel Watch Allegedly Leaks with Circular Design, Rumored to Launch in October

Monday April 12, 2021 2:49 am PDT by
Renders of Google's first smartwatch, codenamed "Rohan," have been shared by Jon Prosser, showing that Google plans to adopt a circular design for its flagship wearable watch. Prosser shared the renders in an episode of his YouTube show "Front Page Tech," in which he claims they were made based on marketing material he had seen from a source within Google. The renders show that the Pixel...
AppleTV and HomePod Feature

Bloomberg: Apple Working on New Apple TV With Integrated HomePod Speaker and FaceTime Camera

Monday April 12, 2021 3:32 am PDT by
Apple is working on a combined Apple TV with HomePod speaker that has a camera for video calls through a connected television set, according to Bloomberg's Mark Gurman. From the report: The company is working on a product that would combine an Apple TV set-top box with a HomePod speaker and include a camera for video conferencing through a connected TV and other smart-home functions,...
nba tracking prompt orange

Two-Thirds of iPhone Users Expected to Block Ad Tracking

Friday April 9, 2021 7:19 am PDT by
As many as 68 percent of iPhone users are expected to deny advertisers permission to track them thanks to Apple's App Tracking Transparency feature, in what is beginning to look like a significant blow to the advertising industry (via AdWeek). With the launch of iOS 14.5, apps will have to receive explicit user permission before accessing an iPhone's advertising identifier or IDFA, which is...
fake airpods 3

Counterfeit 'AirPods 3' Hit the Market Prior to Official Announcement

Friday April 9, 2021 2:45 am PDT by
Apple is expected to launch the third iteration of AirPods in the third quarter of this year. Rumors and reports suggest the new AirPods will feature an updated design more in line with the AirPods Pro, but lacking in "Pro" features such as active noise cancellation. Despite AirPods 3 not yet being officially announced by Apple, counterfeit products of the unreleased earbuds have already hit ...
Top Stories 56 Feature

Top Stories: 'Find My' Expansion, iPhone 13 Pro Mockup, Largest-Ever iMac?

Saturday April 10, 2021 6:00 am PDT by
Apple's AirTags may still be nowhere to be seen nearly two years after signs of them were first discovered, but Apple this week launched its Find My network accessory program that will let third-party devices integrate with the Find My app on Apple's platforms to make it easy to keep track of your items. This week also saw fresh rumors about the upcoming "iPhone 13" and new iMacs, while...
ehric

iPhone 12 Mini Missing From Top 5 Best Selling Smartphone List of January 2021

Friday April 9, 2021 4:58 am PDT by
According to market data compiled by Counterpoint Research, Apple's smallest iPhone since the 2016 iPhone SE, the iPhone 12 mini, struggled to obtain a spot in the top five list of best-selling smartphones in January of this year. According to the market data, the iPhone 12 mini came in eighth place for the best-selling smartphone worldwide in the first month of the year. However, the iPhone ...
sonny 2021 ipad mini pro dummies

Leaked Dummy Units Show iPad Mini 6 With Thick Bezels and Home Button, New iPad Pro Models

Thursday April 8, 2021 2:11 am PDT by
Rumors suggest Apple will release refreshed versions of the iPad mini and iPad Pro models in the first half of this year, potentially as soon as this month, and a new leak today has provided us with a possible preview of what to expect in terms of the devices' overall design and camera prospects. Tech leaker and Apple blogger Sonny Dickson this morning shared images on Twitter showing dummy ...
Google maps feaure green

Google Maps App for iOS Finally Updated After Four Months

Monday April 12, 2021 10:03 am PDT by
Following the completed rollout of App Privacy labels for its App Store apps, Google today updated the Google Maps app for the first time in four months. Apple in December began requiring all new app submissions and app updates to include App Privacy labels, detailing the data that is collected by the app so consumers know what they're sharing. Google didn't begin implementing App Privacy ...
epic iap feature 3

Tim Cook Says App Store Would Become a 'Flea Market' if Third-Party Payment Systems Were Allowed

Monday April 12, 2021 9:41 am PDT by
In a recent interview with the Toronto Star, Apple CEO Tim Cook spoke about a wide variety of topics, ranging from App Tracking Transparency to Apple's ongoing legal battle over App Store policies with Fortnite creator Epic Games. Notably, Cook said that Epic Games' desire for Apple to let developers offer their own payment systems in apps "would make the App Store a flea market":At the...