2014

Apple Releases iOS 7.0.6 With Patch For SSL Connection Verification

ios7.0.6Apple released iOS 7.0.6 for iPhone, iPad, and iPod touch, a minor update that includes a patch for SSL connection verification. The update is available OTA ( over-the-air ) and it’s available for iPhone 4 and later, iPod touch ( 5th generation ) and iPad 2 and later.

From Apple’s knowledge base article on the patch:

Impact: An attacker with a privileged network position may capture or modify data in sessions protected by SSL/TLS

Description: Secure Transport failed to validate the authenticity of the connection. This issue was addressed by restoring missing validation steps.

Two other patches were released yesterday, this one for the Apple TV, and this one for the iPhone 3GS and iPod touch (4th generation).

evasi0n 7 does not support the new update yet. Jailbreakers stay away from that update button for now….