Skip to content

February 25, 2014

Apple Releases OS X 10.9.2 With Fix for Major SSL Vulnerability, FaceTime Audio

by John_A

Apple today released OS X 10.9.2, which includes a fix for a major SSL security flaw that first came to light on Friday, after the release of iOS 7.0.6.

1092
The bug, which was introduced in the form of a single line of errant code that allowed an attacker to bypass SSL/TLS verification routines, left OS X users vulnerable to a man-in-the-middle attack. Shared wired or wireless networks could allow an attacker to intercept communications on affected machines, acquiring sensitive information like login credentials and passwords, or injecting harmful malware.

While the SSL vulnerability was first introduced to iOS in 2012, it only affects Macs running OS X 10.9. Lion and Mountain Lion users are not affected.

OS X 10.9.2 was first seeded to developers in December and has seen seven beta iterations since that time. Along with an emergency fix for the SSL bug, OS X 10.9.2 also includes FaceTime Audio and new blocking controls for iMessage and FaceTime.

It is recommended that all users running OS X 10.9 Mavericks upgrade to OS X 10.9.2 as soon as possible to disable the vulnerability.

    



Read more from News

Leave a comment

Note: HTML is allowed. Your email address will never be published.

Subscribe to comments