Skip to main content

Apple’s OS X security hole affects slew of apps, researcher claims

hackers russia steal 1 billion usernames passwords security
Image used with permission by copyright holder

It looks as if it’s going to be a busy start to the week for Apple’s security team, with more bad news surfacing in connection with a recently publicized ‘gotofail’ vulnerability in its mobile and desktop operating systems.

The tech firm on Friday rolled out an urgent fix for iDevices running iOS 7 after it was discovered it was possible for hackers to obtain a user’s data via a shared Wi-Fi network. Shortly after, it emerged the Safari browser on Mac computers was also affected, with Apple promising to roll out a fix soon.

The situation could be more serious than first feared, however, as a privacy researcher is claiming the bug affects a whole bunch of OS X applications, among them Mail, Twitter, FaceTime, iMessage, iBooks, and even Apple’s software update mechanism, Forbes reported Sunday.

Washington, DC-based Ashkan Soltani posted the list of vulnerable programs on Twitter, which, if accurate, means a hacker could potentially “capture or modify data in sessions protected by SSL/TLS” – in other words, data passing between a computer and servers over a shared network, such as public Wi-Fi, could be intercepted. The advice is to avoid using a Mac computer on such public Wi-Fi networks until Apple rolls out the fix for OS X.

The bug, which first came to light three days ago, has been dubbed ‘gotofail’ because of the single erroneously used ‘goto’ command in the tech giant’s code that caused it. Many in the security community have been puzzled by the apparent simplicity of the error, leading some conspiracy-oriented members to wonder if the code was a calculated move to create a backdoor for spy agencies. Apple, however, has always said it has never enabled backdoor access into any of its products.

Soltani, who describes himself as “an independent researcher and consultant focused on privacy, security, and behavioral economics,” has previously worked on behalf of the Washington Post, helping to analyze documents leaked by Edward Snowden.

[Image: Maksim Kabakou / Shutterstock]

Editors' Recommendations

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Your Siri conversations may have been recorded without your permission
iOS 16 and Mac Ventura on Apple devices.

Apple has patched a security flaw that left macOS and iOS devices vulnerable to having interactions with Siri spied upon and recorded when using accessories such as AirPods or Beats headsets via Bluetooth.

The flaw, which is now referred to as vulnerability CVE-2022-32946, was discovered by app developer Guilherme Rambo, according to Apple Insider.

Read more
macOS Ventura launches with Stage Manager and redesigned apps
Stage manager in macOS Ventura.

Many months after being announced at WWDC 2022, macOS Ventura has now exited beta and is available to download for all.

In addition to a bright orange new wallpaper, the update comes with a number of new features, including Stage Manager, Continuity Camera, and a host of redesigned apps.

Read more
Apple quietly launches unprecedented price cuts to its best MacBook Pros
The back lid of the MacBook Pro.

Apple's top of the line MacBook Pro 16-inch and 14-inch models are some of the best laptops the company has ever made -- but they're extremely expensive machines that rarely come down in price.

However, Apple has quietly dropped the price on these sought-after laptops with some surprising price cuts.

Read more