Apple has fixed a critical vulnerability in its iOS operating system that allowed hackers to impersonate end users visiting websites that do not use encrypted authentication cookies!

The issue lies in the implementation of a cookie store that iOS shares between Safari and a separate built-in browser. The cookie store is used by the operating system to manage various captive portals that are displayed by many Wi-Fi networks when a user first logs in. Captive portals generally require people to authenticate themselves or accept terms of service before gaining access to the network.
“The new vulnerability discovered by Skycure concerns the way iOS handles Cookie Stores when it encounters captive portals. When the operating system connects to such Wi-Fi networks (usually these are the most famous free and paid networks in hotels, airports, cafes, etc.), a window automatically appears on the users’ screen allowing them to use a built-in browser to connect to the network via an HTTP interface. As part of Skycure’s ongoing research into network-based attacks on mobile devices, we found that the built-in browser creates a vulnerability by sharing the cookie store with Safari, the native iOS browser,” Skycure wrote in a blog post.
The attack scenario involves the attacker installing a captive portal on a Wi-Fi network. When a user with a vulnerable iOS device connects to the Wi-Fi, the hacker can exploit this and steal any HTTP cookies stored on the device.
