iPhone, iPad flaw could allow interception of encrypted communications: Apple

Advertisement
By Reuters | Updated: 22 February 2014 12:22 IST
A major flaw in Apple Inc software for mobile devices could allow hackers to intercept email and other communications that are meant to be encrypted, the company said in a Friday afternoon announcement.

If attackers have access to a user's network, such as by sharing the same unsecured wireless service offered by a restaurant, they could see or alter exchanges between the user and protected sites such as Gmail and Facebook, experts said.

"It's as bad as you could imagine, that's all I can say," said Johns Hopkins University cryptography professor Matthew Green.

Apple did not say when or how it learned about the flaw in the way iOS handles sessions in what are known as secure sockets layer or transport layer security, nor did it say whether the flaw was being exploited.

Advertisement

But a statement on its support website was blunt: The software "failed to validate the authenticity of the connection."

Advertisement

Apple released software patches and an update for the current version of iOS for iPhone 4 and later, 5th-generation iPod touches, and iPad 2 and later.

Without the fix, a hacker could impersonate a protected site and sit in the middle as email or financial data goes between the user and the real site, Green said.

Advertisement

Apple did not reply to requests for comment. The flaw appears to be in the way that well-understood protocols were implemented, an embarrassing lapse for a company of Apple's stature and technical prowess.

The company was recently stung by leaked intelligence documents claiming that authorities had 100 percent success rate in breaking into iPhones.

Advertisement

Friday's announcement suggests that enterprising hackers could have had great success as well if they knew of the flaw.

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO 15 Launched in India With Snapdragon 8 Elite Gen 5 SoC at This Price
  2. Poco F8 Ultra Launched With Snapdragon 8 Elite Gen 5 Alongside F8 Pro
  3. Poco F8 Series Launch Today: Know Price, Specs and More
  4. iQOO 15 Launch Today: From Price to Features, Everything You Need to Know
  5. OnePlus 15R to Launch as First Smartphone Globally With This New SoC
  6. Qualcomm Announces the Snapdragon 8 Gen 5 Chipset: All We Know
  7. Vivo X300 FE, OnePlus 15s Tipped to Launch in India Soon
  8. Airtel Ramps Up Xstream Fiber Rollout Amid Surge in India's Connected Homes
  9. Realme Watch 5 India Launch Teased; Will Be Available via This Platform
  10. Huawei MatePad Edge, Watch Ultimate 2 Launched: Check Prices
  1. Poco Pad X1 Launched With Snapdragon 7+ Gen 3 Chipset, 8,850mAh Battery, Alongside Pad M1: Price, Specifications
  2. Gharwali Pedwali OTT Release Date: Know When and Where to Watch This Supernatural Comedy Series Online
  3. Redmi 15C 5G Price in India, Specifications Leaked Again; Could Cost More Than Earlier Expected
  4. Character.AI Introduces Stories, a New Interactive and Shareable Storytelling Format
  5. POCO C85 5G Indian Variant Reportedly Listed on Google Play Console; Design, Key Specifications Revealed
  6. Poco F8 Pro and F8 Ultra With Snapdragon 8 Elite Series SoCs Launched: Price, Specifications and Features
  7. iQOO 15 Launched in India With Snapdragon 8 Elite Gen 5 Chipset, 7,000mAh Battery: Price, Specifications
  8. Qualcomm Announces the Snapdragon 8 Gen 5 Chipset: Features, Specifications
  9. OpenAI Integrates ChatGPT Advanced Voice Mode Directly Within the Chat Interface
  10. OnePlus 15R to Launch as the First Snapdragon 8 Gen 5 SoC-Powered Smartphone Globally
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.