Security Flaw Affects 1500 iOS Apps While Apple's OS X 10.10.3 'Rootpipe' Fix Proves Incomplete [Updated] - MacRumorsOpen MenuShow RoundupsShow Forums menuVisit ForumsOpen Sidebar
Skip to Content

Security Flaw Affects 1500 iOS Apps While Apple's OS X 10.10.3 'Rootpipe' Fix Proves Incomplete [Updated]

apple_security_iconOver the past few days a handful of reports have been accumulating in regards to two security flaws, one affecting roughly 1500 iOS apps and a second affecting OS X users despite Apple having tried to patch the vulnerability on OS X 10.10.3.

The first security flaw is making about 1500 iPhone and iPad apps vulnerable to hackers who could leverage the vulnerability to steal passwords, bank account information, and a handful of other sensitive information, according to Ars Technica. Discovered by security analytics firm SourceDNA last month, the "man-in-the-middle" attack was fixed in a 2.5.2 update to AFNetworking, the open-source code which housed the vulnerability.

Unfortunately, some developers have yet to update to the newest version of the code, leaving those 1500 apps open and vulnerable to the attack, which "can decrypt HTTPS-encrypted data" and essentially allows anyone generating a fake Wi-Fi hotspot access to a user's data on that same Wi-Fi connection. As a result, SourceDNA scanned and analyzed most apps on the App Store for the security flaw, and even created a search tool to discover if a particular app is under risk.

The day the flaw was announced & patched, a quick search in SourceDNA showed about 20,000 iOS apps (out of the 100k apps that use AFNetworking) both contained the AFNetworking library and were updated or released on the App Store after the flawed code was committed. Our system then scanned those apps with the differential signatures to see which ones actually had the vulnerable code.

The results? 55% had the older but safe 2.5.0 code, 40% were not using the portion of the library that provides the SSL API, and 5% or about 1,000 apps had the flaw. Are these apps important? We compared them against our rank data and found some big players: Yahoo!, Microsoft, Uber, Citrix, etc. It amazes us that an open-source library that introduced a security flaw for only 6 weeks exposed millions of users to attack.

Some of the known apps currently vulnerable to the man-in-the-middle attack includes Citrix OpenVoice Audio Conferencing [Direct Link], Alibaba's mobile app [Direct Link], and even Movies by Flixster with Rotten Tomatoes [Direct Link]. SourceDNA urges users to check their most used apps in its search tool for the security flaw, and promises to remove apps that have been fixed and add ones discovered to be vulnerable as time goes on.

The other flaw, called "Rootpipe", dates back to 2011 and has been known for some time. Apple intended to patch the Rootpipe vulnerability in OS X 10.10.3 earlier this month, although older versions of OS X were left vulnerable. But as reported by Forbes, former NSA agent Patrick Wardle has discovered the flaw to still be present on Macs running OS X 10.10.3, as well as older versions.

Apple put additional access controls to stop attacks, but Wardle’s code was still able to connect to the vulnerable service and start overwriting files on his Mac. “I was tempted to walk into the Apple store this [afternoon] and try it on the display models – but I stuck to testing it on my personal laptop (fully updated/patched) as well as my OS X 10.10.3 [virtual machine]. Both worked like a charm,” Wardle told FORBES over email. In a blog post, he’d said his exploit was “a novel, yet trivial way for any local user to re-abuse Rootpipe”.

Discovered last October, the Rootpipe flaw essentially allows a hidden backdoor to be created on a particular system, opening up root access of a computer to a hacker after they obtain local privileges on the device. Physical access or previously granted remote access to the target machine is required in order for the vulnerability to be exploited.

Most recently, Apple faced the "FREAK" security flaw in its systems, making everything from an Apple TV to an iPod touch vulnerable to stolen sensitive information. The company issued a few security updates on all platforms in the weeks following the discovery of the security flaw, beefing up security and working to assuage public concerns. In regards to the man-in-the-middle iOS and re-emerging Rootpipe flaws, the company has yet to comment.

Update: Alamofire Software Foundation has posted a response to the controversy over the AFNetworking issue, refuting SourceDNA's claims about the number of apps affected by noting that even if an app used a vulnerable version of AFNetworking, it would not be susceptible to attack as long as communication is handled over HTTPS with SSL pinning.

If your app communicates over HTTPS and enables SSL pinning, it is not vulnerable to the reported MitM attacks

A significant proportion of apps using AFNetworking took the recommended step of enabling SSL certificate or public key pinning. Those applications are not vulnerable to the reported MitM attacks.

Alamofire's Mattt Thompson tells MacRumors that there is simply no way to tell whether or not an app is vulnerable without trying to to initiate a man-in-the-middle attack, which SourceDNA did not do. Regardless, all developers using AFNetworking in their apps should update to version 2.5.3 immediately.

Popular Stories

Home Hub Command Center with Dome Base Feature

Apple Smart Home Hub to Feature iMac G4-Style Design

Wednesday September 30, 2026 4:36 am PDT by
Apple's long-rumored smart home hub will have an iMac G4-style design and a host of unique features, Bloomberg's Mark Gurman reports. The smart home hub is said to feature a square 6-inch display, with variants that can be placed on a countertop or mounted on a wall. It features a single FaceTime camera on the front, with microphones and speakers in its connected base. Gurman described the...
HomePod minis on gradient feature 1 1

Three New Apple Smart Home Products Coming on October 13

Wednesday September 30, 2026 4:04 am PDT by
Apple plans to introduce a series of new smart home products on Tuesday, October 13, according to Bloomberg's Mark Gurman. Apple reportedly plans to debut its long-awaited smart home hub device, a new HomePod mini, and a new Apple TV on the date. The new HomePod mini and Apple TV are set to retain their existing designs, but tout faster chips to support Siri AI. The new HomePod mini will...
iPhone Duo Open

iPhone Duo Reportedly Facing Production Problems Ahead of Launch

Tuesday September 29, 2026 6:16 am PDT by
The iPhone Duo is reportedly facing production difficulties ahead of its October launch, with early output expected to be limited. A person said to be close to Foxconn's supply chain told China's Jiemian News that final assembly yields for Apple's first foldable iPhone were only slightly above 60% as of September 17. The source said that, under Apple's current quality standards, it could...

Top Rated Comments

ovrlrd Avatar
149 months ago
Pretty silly that Apple can't just bundle this detection into their App Store approvals process. They could also issue massive warnings to app makers and give a deadline to fix or their apps get removed.
Score: 17 Votes (Like | Disagree)
149 months ago
I guess these are some reasons iOS and OS X were the least secure platforms last year. Kinda sucks right?

It's not the platform that is insecure here. It's a third party library that doesn't properly handle HTTPS in an OLDER version that has since been updated and patched. It's the developers of the app that are at fault here.
Score: 16 Votes (Like | Disagree)
149 months ago
Thank you for bringing the rootpipe issue to the front page. More people need to be aware of it so Apple in their best interest will take action to patch it.
Score: 8 Votes (Like | Disagree)
teslo Avatar
149 months ago
'generating a fake wifi hotspot'

i don't know much about this stuff, so does this mean you'd have to willfully join an unknown network because it seemed convenient, or it's a fake wifi network disguised as yours?
Score: 7 Votes (Like | Disagree)
b0nd18t Avatar
149 months ago
I guess these are some reasons iOS and OS X were the least secure platforms last year. Kinda sucks right?
Score: 6 Votes (Like | Disagree)
149 months ago
'generating a fake wifi hotspot'

i don't know much about this stuff, so does this mean you'd have to willfully join an unknown network because it seemed convenient, or it's a fake wifi network disguised as yours?

1. Go to any public place (restaurant, train station, airport, ...)
2. Setup your own Wi-Fi hotspot, no password set
3. Don't call it EvilNetwork, but rather...
4. "Free WiFi"

Be surprised how many people will willfully connect to that "fake" Wi-Fi hotspot...
Score: 5 Votes (Like | Disagree)
Latest Stories
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
New 'AirFly Drive' Accessory Turns Wired CarPlay Into Wireless CarPlay
3 hours ago
Apple Shares Photos Shot on iPhone Duo
Apple Shares Photos Shot on iPhone Duo
4 hours ago
Apple Says iPhone Duo Has Replaceable 'Cover Layer' Above the Display
Apple Says iPhone Duo Has Replaceable 'Cover Layer' Above the Display
5 hours ago
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
Apple's Smart Home Camera Will Apparently Have 'No Video Recording'
7 hours ago
Apple TV Just Updated Its Selection of 'Bonus' Movies
Apple TV Just Updated Its Selection of 'Bonus' Movies
9 hours ago
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
iPhone 18 Pro Colors Buyer's Guide: Which Should You Choose?
9 hours ago
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
Early Prime Big Deal Days: Best Discounts on Accessories, TVs, and More at Amazon
9 hours ago
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
MacBook Pro With OLED Touch Screen Rumored to Launch in October or November
10 hours ago
Apple's All-New Home Hub Rumored to Launch in These Four Colors
Apple's All-New Home Hub Rumored to Launch in These Four Colors
11 hours ago
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
iPhone 18 Pro Aperture Control Goes Fully Manual in Halide 3.2
12 hours ago
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
Apple Stores Receive 'Do Not Open' Boxes Ahead of Smart Home Products Launch
13 hours ago
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
iPhone 18 Pro Sales Jump in China Ahead of iPhone Duo Launch
13 hours ago
Apple TV Still Down for Some Users Following Apple Services Outage
Apple TV Still Down for Some Users Following Apple Services Outage
14 hours ago
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
PSA: Apple Mail on Mac May Stop Syncing Microsoft 365 Accounts Today
14 hours ago
Apple's Smart Home Hub: Everything We Know So Far
Apple's Smart Home Hub: Everything We Know So Far
1 day ago
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
Apple's Home Hub Borrows From the iPhone Duo's StandBy Mode
1 day ago
Apple Invites App Updated With Three New Features
Apple Invites App Updated With Three New Features
1 day ago
Apple Event on October 13?
Apple Event on October 13?
1 day ago
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
Apple Watch SE 3 vs. Series 12 Buyer's Guide: Which Should You Buy?
1 day ago
iPad Mini 8 to Offer These 10 New Features
iPad Mini 8 to Offer These 10 New Features
1 day ago
DoorDash Unveils AI Food Ordering Through Apple's Messages App
DoorDash Unveils AI Food Ordering Through Apple's Messages App
1 day ago
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
Amazon Takes Up to $150 Off Select M5 MacBook Air Models
1 day ago
Apple Still Plans to Release a New Full-Sized HomePod
Apple Still Plans to Release a New Full-Sized HomePod
2 days ago
Apple Working to Expand HomeKit
Apple Working to Expand HomeKit
2 days ago
Apple Smart Home Hub to Feature iMac G4-Style Design
Apple Smart Home Hub to Feature iMac G4-Style Design
2 days ago
Three New Apple Smart Home Products Coming on October 13
Three New Apple Smart Home Products Coming on October 13
2 days ago
Apple Pay Now Available in India With Axis Bank Cards
Apple Pay Now Available in India With Axis Bank Cards
2 days ago
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
OpenAI Launches Always-On 'Dots' Agents to Rival Meta's Muse
2 days ago
AirPods 5 Teardown: Batteries Removable, Case Still Tough
AirPods 5 Teardown: Batteries Removable, Case Still Tough
2 days ago
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
iPhone 18 Pro Owners Complain of Speaker Crackling or Popping
2 days ago

🔗 Related Apple News & Rumors

Stay updated with the latest Apple ecosystem news and verified rumors