# iOS's SSL bug: when was it introduced?

**URL:** <https://boards.straightdope.com/t/ioss-ssl-bug-when-was-it-introduced/683167>\
**Category:** Factual Questions\
**Created:** [March 8, 2014, 3:03am UTC](https://boards.straightdope.com/t/ioss-ssl-bug-when-was-it-introduced/683167 "2014-03-08T03:03:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [March 8, 2014, 3:03am UTC](https://boards.straightdope.com/t/ioss-ssl-bug-when-was-it-introduced/683167/1 "2014-03-08T03:03:44Z")

</div>

Since, despite repeated pleas, I absolutely failed to get an answer in the Pit thread, I ask here.

So there’s a major bug with SSL implementation in iOS 7 that requires an update. But I myself am still on iOS 6 on my iPad. Am I or am I not vulnerable to this bug? Every article I’ve read so far in Google about this all assume that you’ve already updated to iOS7.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [March 8, 2014, 3:28am UTC](https://boards.straightdope.com/t/ioss-ssl-bug-when-was-it-introduced/683167/2 "2014-03-08T03:28:54Z")

</div>

It’s present in iOS 6:

> [@](#):
>
> The SSLVerifySignedServerKeyExchange function in libsecurity\_ssl/lib/sslKeyExchange.c in the Secure Transport feature in the Data Security component in Apple iOS 6.x before 6.1.6 and 7.x before 7.0.6, Apple TV 6.x before 6.0.2, and Apple OS X 10.9.x before 10.9.2 does not check the signature in a TLS Server Key Exchange message, which allows man-in-the-middle attackers to spoof SSL servers by using an arbitrary private key for the signing step or omitting the signing step.
