If you want the security guys at Apple to hear about the issue, you should file a bug directly with them:
http://developer.apple.com/bugreporter/
Then add it in here for the benefit of others: http://openradar.appspot.com
Then add it in here for the benefit of others: http://openradar.appspot.com
The library design decision we don't like is that the IV isn't required; ie, an IV is not among the required arguments of some function in the argument.
There's no reasonable hot fix for this problem. It requires an API change to "fix".
Believe me, please believe me, there are much much worse things that developers will get wrong with AES on the iPhone than not remembering to set a random IV.