Apple patches serious 'triple handshake' bug with iOS 7.1.1, OS X updates

Advertisement
By NDTV Correspondent | Updated: 23 April 2014 21:02 IST
Yet another major security flaw has come to light, and Apple has released updates for its two major operating systems to address it. The HTTP "triple handshake" bug is considered extremely serious because it can be exploited to allow attackers to circumvent encryption on communications which rely on SSL for security.

Ars Technica reports that devices running iOS 7, OS X 10.9.x (Mavericks) and OS X 10.8.x (Mountain Lion) are vulnerable unless they install the latest updates. Apple's release notes for iOS 7.1.1 describe four security-related fixes, including one for the triple handshake bug, known as CVE-1295..

Apple's description doesn't include a severity rating, but describes the potential impact as "An attacker with a privileged network position may capture data or change the operations performed in sessions protected by SSL."

The bug allows attackers trick a client into sending them credentials by spoofing a connection to another trusted server. The credentials could then be reused with other servers, which would simply accept them without question. Apple's fix now ensures that credentials are verified against the original SSL certificate for each connection.

The update comes hot on the heels of another disclosure by Apple that its AirPort Extreme and AirPort Time Capsule routers were vulnerable to the Heartbleed OpenSSL bug. A patch for those products has also been released.

Apple was also forced to issue emergency OS updates in February this year for a security bug dubbed GoToFail, which tricked Web browsers into accepting SSL certificates without legitimate signatures.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  2. Best Mobiles Under Rs. 30,000 in India
  3. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  4. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  5. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  6. ChatGPT App APK Teardown Reportedly Hints at Major UI Upgrades
  1. Motorola Signature, Razr 60 Ultra and More Models Now Eligible to Receive Android 17 Beta Updates
  2. ChatGPT App May Soon Get a Custom Share Sheet, File Picker Interface and More UI Changes
  3. OpenAI Brings ChatGPT to Apple CarPlay, but It Cannot Access Navigation and Live Location Data
  4. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale; iPad, Watch Available With Offers
  5. Google Pixel 11 Pro XL Leaked CAD Renders Reveal Design Identical to Pixel 10 Pro XL
  6. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  7. Oppo F33, Oppo F33 Pro Launch Timeline, Price Range Revealed in New Leak
  8. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  9. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  10. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.