Apple says iOS, OS X, iTunes and iCloud not affected by Heartbleed OpenSSL bug

Advertisement
By NDTV Correspondent | Updated: 11 April 2014 14:24 IST
The Heartbleed bug, which came to light this week, is a massive security vulnerability that affects the encryption framework used by about two-thirds of the world's Web servers, leaving users' passwords and confidential information potentially available to malicious attackers. Since its disclosure, major Web companies have been scrambling to patch their infrastructure and assess the extent of their liability.

While major Web services including Facebook, Dropbox, Yahoo, Amazon and multiple Google offerings are now known to have been vulnerable prior to the disclosure of the bug. Apple has now told tech industry news site Re/code that its products and services were not affected by the bug. Apple has said its operating systems, OS X and iOS, as well as web services including iTunes and iCloud, which are used by millions of users and generate millions of transactions per day, never used the vulnerable OpenSSL implementation.

The OpenSSL Heartbleed bug is being described as one of the most serious security problems to ever affect the Internet. It is not known whether malicious "black hat" hackers were aware of the bug and were exploiting it before security workers were aware of the need to patch it.

Heartbleed allows attackers to send commands to a server which result in it sending small portions of the system memory back to the attacker, unencrypted. Many of these snippets of data could be combined to reveal critical information stored in the memory, including top-level encryption keys and actual user data such as passwords and the contents of messages. With access to such keys, the attackers could then decrypt any information flowing to or from that server, without anyone realising.

Web users are advised to change all passwords, since the worst-case scenario that information has already leaked out, and millions of existing SSL certificates are useless, is completely plausible. In addition to attackers usually motivated by profit, global security agencies that have been in the news for monitoring private communications, are also likely to have been interested in the potential for data gathering using the Heartbleed bug.

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Reno 15 Pro Max, Reno 15 Pro Launched Globally Alongside Reno 15
  2. Here's How Much the Realme 16 Pro Series Could Cost in India
  3. Beauty (2025) OTT Release Date: When and Where to Watch it Online?
  4. Call of Duty: Black Ops 7 Campaign Review: A New Low for the Franchise
  5. TCL Note A1 Nxtpaper E-Note Launched at This Price to Rival Kindle Scribe
  6. Redmi Turbo 5, Turbo 5 Pro Might Be Equipped With These MediaTek Chips
  7. These Three Xiaomi 17 Series Phones Could Launch in India in Q1 2026
  8. LG Just Unveiled These New Xboom Speaker Models Ahead of CES 2026
  9. MediaTek Dimensity 7100 Chipset Launched For Mid-Ranged Phones
  10. Redmi Turbo 5 Pro Charging Details Surface on Chinese Regulator's Website
  1. NASA’s Chandra Spots Champagne Cluster Formed by a Massive Galaxy Collision
  2. NASA’s Curiosity Rover Sends Stunning Sunrise-and-Sunset Holiday Postcard from Mars
  3. Oppo Find X9s Key Specifications Leaked Again; Might Also Launch in India
  4. Redmi Turbo 5, Redmi Turbo 5 Pro to Be Equipped With Upcoming MediaTek Dimensity Chips, Tipster Claims
  5. Vivo V70 Presence on IMDA Certification Database Points to Imminent Release
  6. MediaTek Dimensity 7100 Chipset Launched For Mid-Ranged Phones, Brings Efficiency Gains
  7. JWST Reveals Powerful Winds and Dense Atmosphere on Scorching Exoplanet TOI-561b
  8. New Year 2026 Scam Alert: This WhatsApp Greeting Could Wipe Your Bank Account
  9. Apple Fitness+ Teaser Hints at New Features Coming in January 2026
  10. An AI Pen? Jony Ive and OpenAI’s Secret Hardware Project Details Leak
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.