Release appearance
iOS 4.3.2 Public
Recorded context
About this appearance
iOS 4.3.2 blacklisted fraudulently issued certificates and repaired address disclosure, QuickLook document parsing, and WebKit memory-safety defects.
- Date
- Apr 14, 2011
- Availability
- available
- Revision
- No
Release notes
What changed
Original editorial synthesis. Linked references appear with the claims they support and in the source ledger.
The trust-policy change rejected a set of fraudulently issued SSL certificates that could otherwise support interception of credentials or other sensitive information by an attacker in a privileged network position.[1]
Source ledger
References
Sources are linked to the claims they support. Publication and access dates are shown when available.
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · Certificate Trust Policy
- Apple security updates (2011 to 2012)
Apple Support · Apple · 2023-08-10T00:00:00.000Z · iOS 4.3.2 — 14 Apr 2011
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · libxslt, QuickLook, and WebKit entries
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · iOS 4.3.2 security content
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · libxslt — CVE-2011-0195
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · QuickLook — CVE-2011-1417
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · WebKit — CVE-2011-1290
- About the security content of iOS 4.3.2 Software Update
Apple Support · 2026-07-30 · WebKit — CVE-2011-1344
Release changes
Changed in this release
Features, fixes, removals, and regressions first observed in this release record.
security · fixed
QuickLook Office-file memory safety
Apple documented unexpected application termination or arbitrary code execution as possible outcomes.
- [1] About the security content of iOS 4.3.2 Software Update · QuickLook — CVE-2011-1417
security · fixed
WebKit text-node lifetime
Apple documented browser termination or arbitrary code execution after visiting a crafted website.
- [1] About the security content of iOS 4.3.2 Software Update · WebKit — CVE-2011-1344
security · fixed
WebKit nodeset integer overflow
A malicious page could use the defect to terminate an application or execute code.
- [1] About the security content of iOS 4.3.2 Software Update · WebKit — CVE-2011-1290
security · fixed
libxslt heap-address disclosure
The old behavior could disclose heap addresses to a malicious page and help bypass address-space randomization.
- [1] About the security content of iOS 4.3.2 Software Update · libxslt — CVE-2011-0195
security · fixed
Fraudulent certificate blocklist
This reduced the ability of a privileged network attacker to redirect connections and intercept credentials or other sensitive data using those certificates.
- [1] About the security content of iOS 4.3.2 Software Update · Certificate Trust Policy