• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechApple

Apple iOS 9 Update Fixes Security Bug That Lingered For Two Years

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
January 21, 2016, 6:37 PM ET
The New York Pops Present "Jim Henson's Musical World" - Show
NEW YORK, NY - APRIL 14: The Cookie Monster performs during The New York Pops Present "Jim Henson's Musical World" at Carnegie Hall on April 14, 2012 in New York City. (Photo by Brian Killian/WireImage)Photograph by Brian Killian—WireImage via Getty Images

With its recent iOS 9 software update, Apple has fixed a coding flaw that lingered in its operating system for more than two years after first being reported.

The computer bug let hackers masquerade online as anyone attempting to access certain websites. Prior to the fix, attackers could steal users’ web browsing “cookies”—the identifying data-tags that websites use to recognize return visitors—and use them to impersonate their victims on those sites.

The flaw only impacted sites using default HTTP to shuttle Internet traffic between their computer servers and users. HTTPS-protected sites were not vulnerable.

Get Data Sheet, Fortune’s technology newsletter.

The problem involved how and where Apple’s software had been stashing users’ cookies. At issue was a faulty shared cache. In addition to a device’s Safari browser accessing the cookie store, the bug allowed “captive portals”—another type of browser (think of the login box that automatically pops up when joining a Wi-Fi network at, say, a Starbucks (SBUX))—to access the store as well. Crafty hackers could then exploit this to break inside and steal the cookies.

Skycure, a mobile cybersecurity firm based in Palo Alto, Calif., notified Apple of the vulnerability in June 2013. The two worked together to fix the problem, and Apple acknowledged that it had done so as part of its iOS 9.2.1 software update this month.

“An issue existed that allowed some captive portals to read or write cookies,” the company detailed on a support webpage. “The issue was addressed through an isolated cookie store for all captive portals.”

For more on software bugs, watch:

Skycure provides a more detailed explanation of its researchers’ findings on its company blog. The firm noted that “this is the longest it has taken Apple to fix a security issue reported by us.”

An Apple (AAPL) source described the software fix as being highly complicated, technically speaking, in conversation with Fortune. That echoes the account of the Skycure researchers, who noted that “the fix was more complicated than one would imagine.”

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Databricks co-founder and CEO Ali Ghodsi (right) with Fortune editorial director Andrew Nusca at Fortune Brainstorm AI 2025 in San Francisco. (Photo: Stuart Isett/Fortune)
NewslettersFortune Tech
How Databricks could achieve a trillion-dollar valuation
By Andrew NuscaDecember 10, 2025
9 minutes ago
Zhenghua Yang
SuccessSmall Business
At 18, doctors gave him three hours to live. He played video games from his hospital bed—and now, he’s built a $10 million-a-year video game studio
By Preston ForeDecember 10, 2025
55 minutes ago
AsiaCoupang
Coupang CEO resigns over historic South Korean data breach
By Yoolim Lee and BloombergDecember 10, 2025
3 hours ago
AIpalantir
New contract shows Palantir is working on a tech platform for another federal agency that works with ICE
By Jessica MathewsDecember 9, 2025
10 hours ago
Databricks CEO speaking on stage.
AIBrainstorm AI
Databricks CEO Ali Ghodsi says his company will be worth $1 trillion by doing these three things
By Beatrice NolanDecember 9, 2025
10 hours ago
AIBrainstorm AI
CoreWeave CEO: Despite see-sawing stock, IPO was ‘incredibly successful’ after challenges of Liberation Day tariff timing
By Sharon GoldmanDecember 9, 2025
11 hours ago

Most Popular

placeholder alt text
Economy
‘Fodder for a recession’: Top economist Mark Zandi warns about so many Americans ‘already living on the financial edge’ in a K-shaped economy 
By Eva RoytburgDecember 9, 2025
13 hours ago
placeholder alt text
Success
When David Ellison was 13, his billionaire father Larry bought him a plane. He competed in air shows before leaving it to become a Hollywood executive
By Dave SmithDecember 9, 2025
24 hours ago
placeholder alt text
Banking
Jamie Dimon taps Jeff Bezos, Michael Dell, and Ford CEO Jim Farley to advise JPMorgan's $1.5 trillion national security initiative
By Nino PaoliDecember 9, 2025
15 hours ago
placeholder alt text
Uncategorized
Transforming customer support through intelligent AI operations
By Lauren ChomiukNovember 26, 2025
14 days ago
placeholder alt text
Real Estate
The 'Great Housing Reset' is coming: Income growth will outpace home-price growth in 2026, Redfin forecasts
By Nino PaoliDecember 6, 2025
4 days ago
placeholder alt text
Success
Craigslist founder signs the Giving Pledge, and his fortune will go to military families, fighting cyberattacks—and a pigeon rescue
By Sydney LakeDecember 8, 2025
2 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.