Apple patches serious 'triple handshake' bug with iOS 7.1.1, OS X updates

Advertisement
By NDTV Correspondent | Updated: 23 April 2014 21:02 IST
Yet another major security flaw has come to light, and Apple has released updates for its two major operating systems to address it. The HTTP "triple handshake" bug is considered extremely serious because it can be exploited to allow attackers to circumvent encryption on communications which rely on SSL for security.

Ars Technica reports that devices running iOS 7, OS X 10.9.x (Mavericks) and OS X 10.8.x (Mountain Lion) are vulnerable unless they install the latest updates. Apple's release notes for iOS 7.1.1 describe four security-related fixes, including one for the triple handshake bug, known as CVE-1295..

Apple's description doesn't include a severity rating, but describes the potential impact as "An attacker with a privileged network position may capture data or change the operations performed in sessions protected by SSL."

The bug allows attackers trick a client into sending them credentials by spoofing a connection to another trusted server. The credentials could then be reused with other servers, which would simply accept them without question. Apple's fix now ensures that credentials are verified against the original SSL certificate for each connection.

The update comes hot on the heels of another disclosure by Apple that its AirPort Extreme and AirPort Time Capsule routers were vulnerable to the Heartbleed OpenSSL bug. A patch for those products has also been released.

Apple was also forced to issue emergency OS updates in February this year for a security bug dubbed GoToFail, which tricked Web browsers into accepting SSL certificates without legitimate signatures.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Ray-Ban Meta Gen 2 Glassses Are Now Available in India
  2. Vivo X300 Launched in India With MediaTek Dimensity 9500 SoC at This Price
  3. Samsung Galaxy Z TriFold vs Huawei Mate XT Ultimate Design: A Quick Comparison
  4. Vivo X300 Pro With 200-Megapixel Telephoto Camera Launched in India
  5. Samsung Galaxy S26 vs Galaxy S25: Here Are the Anticipated Upgrades
  6. Samsung Galaxy Z TriFold Launched With 10-Inch Display at This Price
  7. Redmi 15C 5G Camera Details Confirmed a Day Ahead of Launch in India
  8. Amar Subramanya to Replace John Giannandrea as Apple's VP of AI
  9. Gemini App to Get a Major Design Upgrade, Could Soon Be Launched on macOS
  10. Government Says Sanchar Saathi App Is Optional, Can Be Removed
  1. Redmi 15C 5G Launching Today: Know Price in India, Features and Specifications
  2. Gemini App to Get a Major Design Upgrade, Could Soon Be Launched on macOS
  3. NASA’s Perseverance Records First-Ever Mini-Lightning on Mars
  4. Germany to Send First European Astronaut Around the Moon on Artemis Mission
  5. Indian Team Finds 53 Massive Quasars Blasting Jets Millions of Light-Years Long
  6. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  7. Wake Up Dead Man: A Knives Out Mystery OTT Release: When, Where to Watch the Daniel Craig Whodunit
  8. Fire Force Season 3 Release Date: When, Where to Watch the Shonen Anime's Final Arc
  9. Thamma Is Now Available on Amazon Prime: How to Watch Ayushmann Khurrana's Horror Comedy
  10. The Great Shamsuddin Family OTT Release: When, Where to Watch the Peepli Live Director's Comedy Drama
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.