Apple fixes FREAK on iOS, OS X and Apple TV

Apple has announced the latest round of security updates for OS X 10.8, 10.9 and 10.10 (Mountain Lion, Mavericks and Yosemite) that may receive the security update 2015-002. IOS has been updated to version 8.2 and Apple TV is upgraded to version 7.1.

All of the above updates fix the FREAK TLS error and not only.

Apple security

Remember that FREAK is a security flaw that could allow an attacker to fool you and make you think you are on a secure TLS connection while having compromised security using insecure, crackabled encryption keys.

The error was discovered by a group of researchers, three of which were from Microsoft. They initially believed that it only applies to OpenSSL connections and the Secure Transport its system library Apple Lossless Audio CODEC (ALAC),.

But Microsoft quickly realized that its own Schannel TLS library was in jeopardy through it Explorer.

All three platforms (Apple TV, iOS and OS X) are affected by the same Remote Code Execution (RCE) vulnerability, found by Zero of .

The bug was discovered in Apple's IOSurface development framework. IOSurface allows to processes to share the video rendering buffer so that frames can be decompressed by one process but displayed in a separate movie player.

Ironically, as Apple explains, the IOSurface “typically to allow applications to perform image decompression in separate processes to enhance security.”

See all details of the update by Announcement page of Apple.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).