Release appearance
iOS 1.0.1 Public
Recorded context
About this appearance
iPhone software 1.0.1 was the platform’s first public maintenance update, correcting five documented Safari, WebCore, and WebKit security weaknesses.
- Date
- Jul 31, 2007
- Availability
- available
- Revision
- No
Release notes
What changed
Original editorial synthesis. Linked references appear with the claims they support and in the source ledger.
Apple’s first iPhone update focused on web-content security. It corrected cross-site access through redirected windows, unsafe regular-expression processing, injected XMLHttpRequest headers, deceptive internationalized domain names, and memory corruption while rendering framesets.[1]
Source ledger
References
Sources are linked to the claims they support. Publication and access dates are shown when available.
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · iPhone v1.0.1 security content
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · Installation note and version verification
- Apple security updates (25-Jan-2005 to 21-Dec-2007)
Apple Support · Apple · 2026-07-30 · iPhone v1.0.1 Update — 31 July 2007
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · Complete iPhone v1.0.1 security bulletin
- Apple security updates (25-Jan-2005 to 21-Dec-2007)
Apple Support · Apple · 2026-07-30 · iPhone v1.0.1 release date
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · Safari — CVE-2007-2400
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · Safari — CVE-2007-3944
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · WebCore — CVE-2007-2401
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · WebKit — CVE-2007-2399
- About the security content of iPhone v1.0.1 Update
Apple Support · 2026-07-30 · WebKit — CVE-2007-3742
Release changes
Changed in this release
Features, fixes, removals, and regressions first observed in this release record.
security · fixed
Internationalized domain-name validation
Apple described the issue as a way for a malicious site to resemble a legitimate domain in Safari.
- [1] About the security content of iPhone v1.0.1 Update · WebKit — CVE-2007-3742
security · fixed
XMLHttpRequest header validation
The weakness could be triggered by a malicious page crafting invalid HTTP request headers.
- [1] About the security content of iPhone v1.0.1 Update · WebCore — CVE-2007-2401
security · fixed
Frameset rendering memory safety
A maliciously constructed page could otherwise terminate the browser or execute arbitrary code.
- [1] About the security content of iPhone v1.0.1 Update · WebKit — CVE-2007-2399
security · fixed
JavaScript regular-expression validation
Apple documented malicious web content as a route to a crash or arbitrary code execution.
- [1] About the security content of iPhone v1.0.1 Update · Safari — CVE-2007-3944
security · fixed
Safari redirected-window access control
The correction tightened access to window properties during page updates and HTTP redirection.
- [1] About the security content of iPhone v1.0.1 Update · Safari — CVE-2007-2400