your current location:首页 > news>HTTPS vulnerability caused a large number of iOS applications to deposit hidden dangers Alipay is not safe

HTTPS vulnerability caused a large number of iOS applications to deposit hidden dangers Alipay is not safe

2025-02-06 15:41:24|Myriagame |source:minecraft skins

HTTPS

Application analysis service company SourceDNA recently released a report saying that about 1,500 iOS applications have "HTTPS-CRIPPLING" vulnerabilities.This vulnerability allows hackers to intercept user encryption information, such as passwords, bank accounts, or other highly sensitive information.

SourceDNA predicts that more than 2 million users have installed these applications with hidden safety hazards, such as CITRIX OpenVoice Audio Conference, Alibaba.com's mobile applications, KYBANKENT 3.0 and Revo Restaurant Point of Sale.

The vulnerability exists in the early version of Afnetworking.Afnetworking is an open source network development framework that allows driving people to add network functions to their own applications.Although the latest 2.5.2 version has been repaired three weeks ago, at least 1,500 iOS applications still use the 2.5.1 version of hidden dangers.

To use this vulnerability to launch an attack, hackers only need to use the Internet cafes or wifi networks elsewhere elsewhere to monitor iOS devices, and then use a counterfeit concession to launch certificate to launch attacks.Under normal circumstances, this counterfeit certificate will immediately be seen.However, due to the logical errors of version 2.5.1 code, it does not verify the counterfeit certificate, which is considered a legal certificate.

At first SourceDNA did not announce the names of these affected applications so that developers had time to upgrade.Today, SourceDNA provides a search tool that allows iOS users to search according to the developer name.

Last month, Apple fixed the FREAK security vulnerability affecting the iOS system.The vulnerability was a historical residue of a US law in the 1990s. At that time, the legal restrictions on the exit of the RSA encryption key still had many browsers support.