Pangu is the latest tool for jailbreaking devices running iOS 7.1 and above, and is based on an Apple enterprise certificate that allows the installation of applications that do not come from the Apple Store.
The security implications of such a tool are very serious, because this particular certificate gives permission to applications that use it to have several privileges on the user's phone, from intercepting information from the address book and messages to even accessing the camera and microphone functions.
According to Lacoon Security, the Pangu jailbreak tool can be used on all newer iPhone versions (4, 4S, 5S, and 5C), and all iPad versions, including the Air and Mini.
Since the tool is signed with an Apple certificate, Pangu can bypass all security measures on an iOS device and gain elevated privileges, allowing full access to the smartphone or tablet.
Ohad Bobrov of Lacoon Security says that the certificate used for the Pangu app is associated with the company “Hefei Bo Fang Communication Technology Co. Ltd.”
We have no information about how the hackers managed to obtain such a certificate, which Apple makes available to a small number of companies, after a thorough investigation, which determines whether there is any risk of abuse.
In this case, Apple will likely have to take the necessary steps to revoke the specific certificate.
The vulnerabilities used by the Pangu developers were discovered by Stefan Esser, a well-known iOS platform researcher. Esser shared some iOS exploits for educational purposes, but he kept many important details to himself. As for the information he shared, he did not give his permission for anyone to use it.
The researcher reported that Pangu developers offered to buy iOS exploits, but refused to sell them.
[tweet_embed id=482004118698217472]
[tweet_embed id=481923306371944450]

