BlackBerry to release BBM patches to fix Heartbleed bug vulnerabilities

Advertisement
By Reuters | Updated: 14 April 2014 10:21 IST
BlackBerry Ltd said it plans to release security updates for messaging software for Android and iOS devices by Friday to address vulnerabilities in programs related to the "Heartbleed" security threat.

Researchers last week warned they uncovered Heartbleed, a bug that targets the OpenSSL software commonly used to keep data secure, potentially allowing hackers to steal massive troves of information without leaving a trace.

Security experts initially told companies to focus on securing vulnerable websites, but have since warned about threats to technology used in data centers and on mobile devices running Google Inc's Android software and Apple Inc's iOS software.

Scott Totzke, BlackBerry senior vice president, told Reuters on Sunday that while the bulk of BlackBerry products do not use the vulnerable software, the company does need to update two widely used products: Secure Work Space corporate email and BBM messaging program for Android and iOS.

Advertisement

He said they are vulnerable to attacks by hackers if they gain access to those apps through either WiFi connections or carrier networks.

Advertisement

Still, he said, "The level of risk here is extremely small," because BlackBerry's security technology would make it difficult for a hacker to succeed in gaining data through an attack.

"It's a very complex attack that has to be timed in a very small window," he said, adding that it was safe to continue using those apps before an update is issued.

Advertisement

Google spokesman Christopher Katsaros declined comment. Officials with Apple could not be reached.

Security experts say that other mobile apps are also likely vulnerable because they use OpenSSL code.

Advertisement

Michael Shaulov, chief executive of Lacoon Mobile Security, said he suspects that apps that compete with BlackBerry in an area known as mobile device management are also susceptible to attack because they, too, typically use OpenSSL code.

He said mobile app developers have time to figure out which products are vulnerable and fix them.

"It will take the hackers a couple of weeks or even a month to move from 'proof of concept' to being able to exploit devices," said Shaulov.

Technology firms and the U.S. government are taking the threat extremely seriously. Federal officials warned banks and other businesses on Friday to be on alert for hackers seeking to steal data exposed by the Heartbleed bug.

Companies including Cisco Systems Inc, Hewlett-Packard Co, International Business Machines Corp, Intel Corp, Juniper Networks Inc, Oracle Corp Red Hat Inc have warned customers they may be at risk. Some updates are out, while others, like BlackBerry, are rushing to get them ready.

While there have been no public reports of successful attacks involving the Heartbleed vulnerability, researchers say that it has been around for several years. That means that hackers could have successfully been using it without being caught since attacks do not leave any traces.

© Thomson Reuters 2014
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. How to Reset Your Instagram Reels Algorithm
  2. iQOO 15R Battery Capacity, Thickness Announced by Company
  3. Nothing Phone 4a Series Tipped to Launch Globally on This Date
  4. OpenAI Introduces Codex App With Agentic Coding for macOS
  5. Oakley Meta Glasses Now Available in India for Athletes
  6. Realme Buds Air 8 Review: Big on Features, but There's A Catch
  7. Redmi K Pad 2 Tipped to Feature Bose-Tuned Speakers and This MediaTek Chip
  1. Parasakthi OTT Release Revealed: When and Where to Watch Sivakarthikeyan Starrer Movie Online?
  2. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra: Expected Specifications, Features
  3. Sampradayini Suppini Suddapoosani Now Streaming Online: What You Need to Know
  4. Lucky The Superstar OTT Release Date Revealed: Know When and Where to Watch This Upcoming Tamil Comedy Drama Film
  5. Redmi K Pad 2 Tipped to Launch With MediaTek Dimensity 9500 SoC, Bose-Tuned Speakers
  6. Nioh 3 Will Be a PS5 Console Exclusive for 6 Months, Could Launch on Other Platforms Later This Year
  7. Nothing Phone 4a Series Tipped to Launch Globally Next Month: Expected Specifications, Features
  8. Vivo X200T With Triple 50-Megapixel Zeiss Cameras Goes on Sale in India: Price, Offers
  9. Infinix Note 60, Note 60 Pro, Note 60 Ultra Memory Variants Leaked Ahead of Anticipated Launch in India
  10. OpenAI Introduces Codex App With Agentic Coding for macOS
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.