After the announcement of Heartbleed , the internet community realized how vulnerable it is. Security experts confirmed the vulnerability while system administrators are trying to “patch” security holes in places that until recently were taken for granted. In the meantime, it became known that not only websites are affected, but also millions of smartphones and tablets.
Heartbleed is a critical bug (CVE-2014 – 0160) in the popular OpenSSL encryption application, which allows attackers to read portions of the affected server's memory, potentially revealing user data such as names, passwords, credit card numbers, and more.
While most websites report that they have fixed the problem, let's remember that there are around 40-60 billion active Smartphone applications that may be shared by Heartbleed, as they use OpenSSL to connect to various servers.
So let's see what happens with the most popular mobile operating systems.
ANDROID
Google said in a blog post that Android is not vulnerable to the Heartbleed bug, except for one very specific version.
Android 4.1.1 Jelly Bean uses the vulnerable version of OpenSSL.
Google has not disclosed how many devices are vulnerable to the bug, but according to the company, it is estimated that about 34.4% of Android devices run Android 4.1.x.
Last September, Google announced that it had activated one billion devices. This means that the minimum number of devices affected is likely in the millions.
Google has already released patches for Android 4.1.1, but as is known, the update will be released by device manufacturers and mobile carriers.
APPLE
Apple device users can rest easy. Devices running iOS and OS X are not affected by Heartbleed.
"Apple takes security very seriously. iOS and OS X do not use the vulnerable software, and core services and web-based services are not affected," Apple told Re/code.
Instead of using OpenSSL, Apple uses a different SSL/TLS library called Secure Transport. In February, a vulnerability was discovered in Secure Transport that allowed man-in-the-middle (MitM) attacks. Although the vulnerability was not as severe as the OpenSSL Heartbleed bug.
Apple users should be cautious, however, as those using BBM for private messaging on iOS may be vulnerable to the vulnerability.
BLACKBERRY
BlackBerry has confirmed that some of its products, such as Secure Work Space for iOS and Android, BlackBerry Link for Windows and Mac OS, and even BBM for iOS and Android, are vulnerable to Heartbleed. The number of users affected reaches 80 million (that's how many use the BBM service).
The company assured that BlackBerry Smartphones and tablets, BlackBerry Enterprise Server 5, and BlackBerry Enterprise Service 10, are not affected by the flaw and are fully protected.

