Filed under: Bugs/Recalls, iPhone, Jailbreak/pwnage
iPhone push on unlocked phones sends AIM message to unintended recipients
Update 7/22: AOL has responded to the reports of misdirected push notifications, and has confirmed that the issue is due to the use of a workaround for push notifications on unlocked phones.
--
If you want to have a hot and steamy exchange with your sweetheart via AIM on the iPhone, you might want to think again -- if you have an unlocked or jailbroken phone.
CrunchGear reports that Till Schadde with Equinux has discovered an iPhone bug where AIM messages could be sent to random people without you even knowing it. Schadde discovered this when he was notified that a message he had sent to his iPhone version of AIM got intercepted by someone else. That person proceeded to contact Schaddle, sharing the screenshot shown at right with him. Schadde posted the screenshot and detailed the bug on Twitter after testing it once more from his computer.
The bug is being blamed on iPhone 3.0's push notification and seems to be limited to unlocked/jailbroken iPhones at the moment.
Edit (12:20 PT): Schadde has tweeted that he was contacted by AOL via phone this morning, and they are currently investigating the issue.
[Via CrunchGear]

This vulnerability is patched in the 
There's a lot of "could" and "might" in this story, folks, so keep that in mind. MacNN is reporting that a group of iPhone developers has identified a bug in the current iPhone firmware that could lead to an exploit of the Default.png file.
The distance between good intentions and actual results seems to be getting longer and longer. While Apple did
The UK's IT Week
I
take security exploits seriously. I'm responsible for many hundreds of Macintosh computers that reside in many
different environments, not to mention half-a-dozen X-Serves, several of which are production boxes open to the world.
When a security exploit is announced, I look to see if it will impact my workstations and servers and whether I need to
take immediate action. And with the exception of the recent Safari exploit that was patched last week by 
![TUAW [Cafepress]](http://www.blogsmithmedia.com/www.tuaw.com/media/tuaw-cafepress-promo.png)

