Apple delivers updates related to Comodo, Pwn2Own

Apple on Thursday released security updates for its Mac OS X operating system and Safari web browser, as well as a number of other products in its portfolio, including the iPhone, iPad, iTouch and Apple TV.

The Mac OS X update, for versions 10.5 and 10.6, solely addresses the recent theft of nine digital certificates from Comodo. 

A fraudster could have used the fake SSL certificates – issued for sites such as Google, Yahoo, Skype and Microsoft's Hotmail – to create a fake website that was able to bypass a browser's validity mechanism and appear like the real thing to users. The attacker would then be able to spoof content or perform phishing and man-in-the-middle attacks to steal credentials or spy on users. The fix issued on Thursday places the toxic certificates on a blacklist so they can't be used on Safari.

Meanwhile, the newly issued Safari 5.0.5 addresses two vulnerabilities that could have led to unexpected application termination or arbitrary code execution if a user visits a malicious website.

Apple's mobile device suite also saw fixes with the release of iOS 4.3.2 8H8 (4.2.7 for VZ iPhone). Among the issues addressed are bugs exposed during CanSecWest's Pwn2Own hacker competition last month in Vancouver.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.