Sandbox

Early versions of the iPhone software in the pre-iOS era did not include any kind of application sandbox. This gave apps more power on the device than they should have and meant that exploits against the phone often gave attackers root access to the iPhone software. Apple addressed this with the addition of the Apple Sandbox for iOS, which is a fine-grained set of restrictions on what apps can do and what actions they can take on the user’s behalf.

Early versions of the iPhone software in the pre-iOS era did not include any kind of application sandbox. This gave apps more power on the device than they should have and meant that exploits against the phone often gave attackers root access to the iPhone software. Apple addressed this with the addition of the Apple Sandbox for iOS, which is a fine-grained set of restrictions on what apps can do and what actions they can take on the user’s behalf. The sandbox is designed to prevent exploits against the software from blowing away all of the security restrictions by limiting the post-exploitation options.

Suggested articles

2020 Cybersecurity Trends to Watch

Mobile becomes a prime phishing attack vector, hackers will increasingly employ machine learning in attacks and cloud will increasingly be seen as fertile ground for compromise.

Top Mobile Security Stories of 2019

Cybercrime increasingly went mobile in 2019, with everything from Apple iPhone jailbreaks and rogue Android apps to 5G and mobile-first phishing dominating the news coverage. Here are Threatpost’s Top 10 mobile security stories of 2019.