Code audit finds over 25,000 vulnerable apps in iTunes

By
Follow google news

Bug in SSL library makes eavesdropping easy.

A serious flaw in the traffic encryption and session validation component of the open source framework used by many iOS developers for their apps sold on iTunes could leave thousands of users' traffic open to eavesdropping.

Code audit finds over 25,000 vulnerable apps in iTunes

SourceDNA found that the AFNetworking framework for Apple iOS and OS X operating systems does not default to checking domain names for TLS/SSL (Transport Layer Security/Secure Sockets Layer) sessions in version 2.5.2 and prior.

All an attacker needed to do to exploit the flaw, SourceDNA said, was to obtain a cheap, legitimate SSL certificate for a web server to intercept user communications sessions that appear to be secured, by pretending to be any domain as the name is not validated.

Currently, over 25,000 apps in the Apple iTunes store use a vulnerable version of AFNetworking.

Using certificate pinning - a technique that tells browsers only to accept specific certificates - would enable domain validation. However, SourceDNA noted that few iOS developers turn on certificate pinning, and recommended that the technique is used more frequently for additional security.

SourceDNA had earlier discovered through a code audit that AFNetworking would accept self-signed SSL certificates, meaning anyone could create these and present them as being legitimate to users - a scenario SourceDNA called "game over" as it could lead to widespread breaking of SSL security.

Versions 2.5.3 of AFNetworking contain a bug fix for the lack of SSL certificate domain name validation.

The security vendor encouraged developers to track their source code to ensure that the components used are the most recent with security fixes applied.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

National photo licence recognition system set to go live in 2025

National photo licence recognition system set to go live in 2025

Hackers using F5 devices to target US gov networks

Hackers using F5 devices to target US gov networks

Qantas says customer data released by cyber criminals

Qantas says customer data released by cyber criminals

Austrade to replace its data centre core network

Austrade to replace its data centre core network

Log In

  |  Forgot your password?