• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechApple

Apple iOS 9 Update Fixes Security Bug That Lingered For Two Years

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
January 21, 2016, 6:37 PM ET
The New York Pops Present "Jim Henson's Musical World" - Show
NEW YORK, NY - APRIL 14: The Cookie Monster performs during The New York Pops Present "Jim Henson's Musical World" at Carnegie Hall on April 14, 2012 in New York City. (Photo by Brian Killian/WireImage)Photograph by Brian Killian—WireImage via Getty Images

With its recent iOS 9 software update, Apple has fixed a coding flaw that lingered in its operating system for more than two years after first being reported.

The computer bug let hackers masquerade online as anyone attempting to access certain websites. Prior to the fix, attackers could steal users’ web browsing “cookies”—the identifying data-tags that websites use to recognize return visitors—and use them to impersonate their victims on those sites.

The flaw only impacted sites using default HTTP to shuttle Internet traffic between their computer servers and users. HTTPS-protected sites were not vulnerable.

Get Data Sheet, Fortune’s technology newsletter.

The problem involved how and where Apple’s software had been stashing users’ cookies. At issue was a faulty shared cache. In addition to a device’s Safari browser accessing the cookie store, the bug allowed “captive portals”—another type of browser (think of the login box that automatically pops up when joining a Wi-Fi network at, say, a Starbucks (SBUX))—to access the store as well. Crafty hackers could then exploit this to break inside and steal the cookies.

Skycure, a mobile cybersecurity firm based in Palo Alto, Calif., notified Apple of the vulnerability in June 2013. The two worked together to fix the problem, and Apple acknowledged that it had done so as part of its iOS 9.2.1 software update this month.

“An issue existed that allowed some captive portals to read or write cookies,” the company detailed on a support webpage. “The issue was addressed through an isolated cookie store for all captive portals.”

For more on software bugs, watch:

Skycure provides a more detailed explanation of its researchers’ findings on its company blog. The firm noted that “this is the longest it has taken Apple to fix a security issue reported by us.”

An Apple (AAPL) source described the software fix as being highly complicated, technically speaking, in conversation with Fortune. That echoes the account of the Skycure researchers, who noted that “the fix was more complicated than one would imagine.”

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Fortune Brainstorm Tech 2019 in Aspen, Colo. (Photo: Fortune)
NewslettersFortune Tech
Who’s speaking at Fortune Brainstorm Tech 2026
By Andrew NuscaApril 10, 2026
31 minutes ago
Schools across America are quietly admitting that screens in classrooms made students worse off and are reversing years of tech-first policies
InnovationEducation
Schools across America are quietly admitting that screens in classrooms made students worse off and are reversing years of tech-first policies
By Marco Quiroz-GutierrezApril 10, 2026
1 hour ago
Dario Amodei
NewslettersTerm Sheet
What Anthropic’s too-dangerous-to-release AI model means for its upcoming IPO
By Beatrice NolanApril 10, 2026
1 hour ago
Even Nvidia’s own research teams can’t get enough GPUs amid the race for AI computing power
NewslettersEye on AI
Even Nvidia’s own research teams can’t get enough GPUs amid the race for AI computing power
By Sharon GoldmanApril 9, 2026
17 hours ago
You’re looking at the AI revolution all wrong, top economist says: 40% unemployment and a 3-day work week are the same thing
AIdisruption
You’re looking at the AI revolution all wrong, top economist says: 40% unemployment and a 3-day work week are the same thing
By Nick LichtenbergApril 9, 2026
17 hours ago
Zoom CEO Eric Yuan
Successthe future of work
‘I hate working 5 days’: Zoom CEO says traditional work schedules are becoming obsolete—and predicts a 3-day workweek by 2031
By Preston ForeApril 9, 2026
18 hours ago

Most Popular

The U.S. government is spending $88 billion a month in interest on national debt—equal to spending on defense and education combined
Economy
The U.S. government is spending $88 billion a month in interest on national debt—equal to spending on defense and education combined
By Fortune EditorsApril 9, 2026
22 hours ago
A Meta employee created a dashboard so coworkers can compete to be the company's No. 1 AI token user—and Zuckerberg doesn't even rank in the top 250
AI
A Meta employee created a dashboard so coworkers can compete to be the company's No. 1 AI token user—and Zuckerberg doesn't even rank in the top 250
By Fortune EditorsApril 9, 2026
1 day ago
Gen Z doesn't want your full-time job. They want several part-time roles, and it's reshaping the entire workforce
Success
Gen Z doesn't want your full-time job. They want several part-time roles, and it's reshaping the entire workforce
By Fortune EditorsApril 9, 2026
1 day ago
White-collar workers are quietly rebelling against AI as 80% outright refuse adoption mandates
AI
White-collar workers are quietly rebelling against AI as 80% outright refuse adoption mandates
By Fortune EditorsApril 9, 2026
23 hours ago
Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout
AI
Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout
By Fortune EditorsApril 8, 2026
2 days ago
Current price of oil as of April 9, 2026
Personal Finance
Current price of oil as of April 9, 2026
By Fortune EditorsApril 9, 2026
21 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.