Apple Confirms 'Heartbleed' Security Issue Did Not Affect Apple Software and 'Key Services'

heartbleed_200Apple today released a statement to Re/code confirming that iOS, OS X and "key web services" were unaffected by the widely publicized security flaw known as Heartbleed which was disclosed earlier this week.

“Apple takes security very seriously. iOS and OS X never incorporated the vulnerable software and key web-based services were not affected,” an Apple spokesperson told Re/code.

Heartbleed was a security flaw in the popular open-source software OpenSSL which helps provide secure connections between clients and servers. Due the ubiquity of OpenSSL, Heartbleed is believed to have affected approximately 66% of the internet.

Security blogger Bruce Schneier describes the issue as "catastrophic" and on "the scale of 1 to 10, this is an 11." The flaw allowed servers to leak server memory to a malicious attacker, allowing hackers to extract login/password and other private data from a server. Users are recommended to change their passwords on all services that may have been affected. Mashable provides a list of services where you should change your password. Fortunately, MacRumors Forums were unaffected by the security flaw.

Top Rated Comments

Jedibugs Avatar
105 months ago
That's good. You know if Apple had been affected, all the headlines would be reading "Apple's Security Failure"
Score: 19 Votes (Like | Disagree)
BornAgainApple Avatar
105 months ago
This is what a Walled Garden gets you :apple:
Score: 19 Votes (Like | Disagree)
dugbug Avatar
105 months ago
Apple could not resist that zinger :p

Android apparently incorporated it. Ouch.
Score: 19 Votes (Like | Disagree)
robeddie Avatar
105 months ago
To people above me: right - remember SSL issue from not long ago?
The garden is walled, except for wholes found from time to time.

wholes?

hmm, I'm gonna think about that while I enjoy my hore.
Score: 15 Votes (Like | Disagree)
petsounds Avatar
105 months ago

It's not important that Apple takes security very seriously and it doesn't even matter in this case - nobody (maybe except for the NSA^^) knew about this issue, so there wouldn't have been anything Apple could have done.
Not exactly. OpenSSL has gotten a lot of flack in the past for being a shoddy library. There's plenty of security researchers who've looked through the code and said it's a mess. So perhaps Apple knew to stay away where possible. In other cases, it was a lucky accident that they pinned OpenSSL on OS X to the older 0.9.8 which wasn't vulnerable.

Either way, it's a PR win for Apple, especially compared to Android which is vulnerable. And you can bet that many of the old versions of Android people are running will never get patched by carriers.
Score: 14 Votes (Like | Disagree)
SILen(e Avatar
105 months ago
Their statement contained a bit of marketing blahblah.

It's not important that Apple takes security very seriously and it doesn't even matter in this case - nobody (maybe except for the NSA^^) knew about this issue, so there wouldn't have been anything Apple could have done.
Score: 13 Votes (Like | Disagree)

Popular Stories

maxresdefault

Samsung's New 32-Inch 'M8' Display vs. Apple's Studio Display

Thursday April 21, 2022 1:14 pm PDT by
Samsung recently introduced the M8, a new 32-inch 4K display that's priced at $700, making it less than half as expensive as the Studio Display from Apple. We picked up one of the displays and thought we'd compare it to the Studio Display in our latest YouTube video to see how it performs and whether you can save some money by going with a cheaper option. Subscribe to the MacRumors YouTube ...
macos server

Apple Discontinues macOS Server

Thursday April 21, 2022 10:30 am PDT by
Apple today announced in a support document that macOS Server is being discontinued as of April 21, 2022. Apple has been phasing out macOS Server for several years now, and the company is finally ready to shut it down for good. macOS Server 5.12.2 will be the last version of the app, and macOS Server services have now been migrated to macOS. Popular macOS Server capabilities that include...
USB C Over Lightning Feature

EU Moves One Step Closer to Mandating Apple to Switch iPhone, iPad, and AirPods to USB-C

Thursday April 21, 2022 7:54 am PDT by
Members of the European Parliament this week voted overwhelmingly in support of legislation that will compel Apple to offer a USB-C port on all iPhones, iPads, and AirPods in Europe. The proposal, known as a directive, will force all consumer electronics manufacturers who sell devices in Europe to ensure that all new phones, tablets, laptops, digital cameras, headphones, headsets, handheld...
iPhone 14 Mock pill and hole

Kuo: iPhone 14 Models Likely to Feature Upgraded Front Camera With Autofocus

Tuesday April 19, 2022 7:46 am PDT by
All four iPhone 14 models that are expected to launch later this year will likely feature an upgraded front camera with autofocus and a wider ƒ/1.9 aperture, well-known Apple analyst Ming-Chi Kuo said in a tweet today. The wider aperture would allow more light to pass through the lens and reach the front camera's sensor on iPhone 14 models. Kuo said these camera upgrades could result in an...
iphone 12 box

Apple Must Compensate Brazilian Customer Over $1,000 for Selling iPhone Without a Charger, Judge Rules

Wednesday April 20, 2022 7:34 am PDT by
Apple must compensate a Brazilian customer who recently purchased an iPhone for selling the device without a charger included in the box, which violates consumer law, a judge has ruled. Apple's decision to remove the charger in the box sparked controversy in 2020. Apple claims the move is for environmental reasons, claiming the decision is equivalent to removing nearly 450,000 cars from the...
iphone 13 pro and 14 pro render with background

iPhone 14 Pro Rumored to Feature Rounder Design to Match Larger Rear Camera Array

Thursday April 21, 2022 9:57 am PDT by
The iPhone 14 Pro could feature significantly rounder corners to match the larger rear camera array, according to Apple concept graphic renderer Ian Zelbo. Zelbo, who is best known for creating renders of upcoming Apple devices based on leaked information, including the Mac Studio, Studio Display, rumored mixed-reality headset, and more, believes that the iPhone 14 Pro models are likely to...
Transcend JDL330 2

Transcend Announces 1TB JetDrive Lite 330 Expansion Card for 14-inch and 16-inch MacBook Pro

Thursday April 21, 2022 4:38 am PDT by
Transcend has announced a 1TB version of its JetDrive Lite 330 expansion cards for 14-inch and 16-inch MacBook Pro models, providing users of Apple's latest Macs with an affordable way to increase internal storage capacity. Transcend says the JetDrive Lite 330 cards are built with high-quality NAND flash, offering read and write speeds of up to 95MB/s and 75MB/s, respectively. Once the...
apple cash visa hero

New Apple Cash Accounts Now Branded as Visa Cards

Friday April 22, 2022 5:55 am PDT by
The Apple Cash virtual debit card appears to be switching networks from Discover to Visa, as revealed in some updated images on Apple's website and noted by Twitter user @Kanjo. Since its launch, Apple Cash (originally known as Apple Pay Cash) has been operated through a partnership with Green Dot Bank on the Discover network. Discover is one of the smaller card networks and is accepted in...
magsafe battery pack on iphone

MagSafe Battery Pack Now Able to Charge at Faster 7.5W Speed After Firmware Update

Wednesday April 20, 2022 1:09 pm PDT by
Apple yesterday released a firmware update designed for the MagSafe Battery Pack, and it turns out the new firmware enables 7.5W charging while on the go, up from the previous 5W limit. In an support document, Apple says that MagSafe Battery Pack owners can update their firmware to the new 2.7.b.0 release to get the faster 7.5W charging capabilities. Updating the MagSafe Battery Pack can...