updated 01:35 pm EDT, Tue August 3, 2010
Temporary fix available from jailbreak community
The JailbreakMe hack for iOS devices is in fact based on a serious PDF exploit in Safari, claims security specialist Charlie Miller. The trigger for the exploit is currently believed to be a font bug which allows the site to gain deep access to the iOS firmware. "Scary how it totally defeats Apple's security architecture," Miller remarks.
There is no known way of closing the vulnerability at the moment, but it should be possible to prevent a PDF from loading automatically. The method involves installing a special DEB file on a device, which forces users to confirm that it's alright to open a PDF document. Users must, however, already have a jailbroken device in order for the technique to work.