Release appearance
iOS 4.0.2 Public
Recorded context
About this appearance
iOS 4.0.2 was a focused security update that repaired a crafted-PDF font vulnerability and an IOSurface privilege-escalation path.
- Date
- Aug 11, 2010
- Availability
- available
- Revision
- No
Release notes
What changed
Original editorial synthesis. Linked references appear with the claims they support and in the source ledger.
Apple’s dedicated advisory identifies two corrections in iOS 4.0.2. One added bounds checking to FreeType’s handling of embedded CFF font instructions, where a malicious PDF could execute code.[1]
Source ledger
References
Sources are linked to the claims they support. Publication and access dates are shown when available.
- About the security content of the iOS 4.0.2 Update for iPhone and iPod touch
Apple Support · 2026-07-30 · FreeType — CVE-2010-1797
- About the security content of the iOS 4.0.2 Update for iPhone and iPod touch
Apple Support · 2026-07-30 · IOSurface — CVE-2010-2973
- About the security content of the iOS 4.0.2 Update for iPhone and iPod touch
Apple Support · 2026-07-30 · iOS 4.0.2 security content
Release changes
Changed in this release
Features, fixes, removals, and regressions first observed in this release record.
security · fixed
Crafted PDF font bounds checking
The flaw could allow arbitrary code execution when viewing a malicious PDF containing a crafted embedded font.
- [1] About the security content of the iOS 4.0.2 Update for iPhone and iPod touch · FreeType — CVE-2010-1797
security · fixed
IOSurface privilege boundary
Apple described the prerequisite as malicious code already running with user privileges; the corrected validation prevented that code from escalating through IOSurface.
- [1] About the security content of the iOS 4.0.2 Update for iPhone and iPod touch · IOSurface — CVE-2010-2973