Apple patches serious 'triple handshake' bug with iOS 7.1.1, OS X updates

Advertisement
By NDTV Correspondent | Updated: 23 April 2014 21:02 IST
Yet another major security flaw has come to light, and Apple has released updates for its two major operating systems to address it. The HTTP "triple handshake" bug is considered extremely serious because it can be exploited to allow attackers to circumvent encryption on communications which rely on SSL for security.

Ars Technica reports that devices running iOS 7, OS X 10.9.x (Mavericks) and OS X 10.8.x (Mountain Lion) are vulnerable unless they install the latest updates. Apple's release notes for iOS 7.1.1 describe four security-related fixes, including one for the triple handshake bug, known as CVE-1295..

Apple's description doesn't include a severity rating, but describes the potential impact as "An attacker with a privileged network position may capture data or change the operations performed in sessions protected by SSL."

The bug allows attackers trick a client into sending them credentials by spoofing a connection to another trusted server. The credentials could then be reused with other servers, which would simply accept them without question. Apple's fix now ensures that credentials are verified against the original SSL certificate for each connection.

The update comes hot on the heels of another disclosure by Apple that its AirPort Extreme and AirPort Time Capsule routers were vulnerable to the Heartbleed OpenSSL bug. A patch for those products has also been released.

Apple was also forced to issue emergency OS updates in February this year for a security bug dubbed GoToFail, which tricked Web browsers into accepting SSL certificates without legitimate signatures.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a Series Tipped to Launch Globally on This Date
  2. How to Reset Your Instagram Reels Algorithm
  3. Google Might Be Making It Hassle-Free to Switch From ChatGPT to Gemini
  4. OpenAI Introduces Codex App With Agentic Coding for macOS
  5. Infinix Note 60, Note 60 Pro, Note 60 Ultra May Be Sold in These Variants
  6. Oppo Find X10 Pro Tipped to Arrive With This Camera Upgrade
  7. Oakley Meta Glasses Now Available in India for Athletes
  8. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra
  9. iQOO 15R Battery Capacity, Thickness Announced by Company
  10. Vivo X200T Is Now Available for Purchase in India: See Price, Offers
  1. NASA’s Perseverance Makes History on Mars with Claude AI at the Helm
  2. Mozilla Firefox Will Let You Decide How Much AI You Want in Your Browser
  3. Oppo Find X10 Pro Will Launch With Two 200-Megapixel Rear Cameras, Tipster Claims
  4. Psych Siddhartha OTT Release Date: When and Where to Watch it Online?
  5. Parasakthi OTT Release Revealed: When and Where to Watch Sivakarthikeyan Starrer Movie Online?
  6. Vivo X300 Max Tipped to Launch in March Alongside the Vivo X300 Ultra: Expected Specifications, Features
  7. Sampradayini Suppini Suddapoosani Now Streaming Online: What You Need to Know
  8. Lucky The Superstar OTT Release Date Revealed: Know When and Where to Watch This Upcoming Tamil Comedy Drama Film
  9. Redmi K Pad 2 Tipped to Launch With MediaTek Dimensity 9500 SoC, Bose-Tuned Speakers
  10. Nioh 3 Will Be a PS5 Console Exclusive for 6 Months, Could Launch on Other Platforms Later This Year
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.