Release appearance

iOS 4.3.2 Public

Full article
Public release

Recorded context

About this appearance

iOS 4.3.2 blacklisted fraudulently issued certificates and repaired address disclosure, QuickLook document parsing, and WebKit memory-safety defects.

Date
Apr 14, 2011
Availability
available
Revision
No

Release notes

What changed

Original editorial synthesis. Linked references appear with the claims they support and in the source ledger.

The trust-policy change rejected a set of fraudulently issued SSL certificates that could otherwise support interception of credentials or other sensitive information by an attacker in a privileged network position.[1]

The update also stopped an XPath function from exposing heap addresses, corrected a QuickLook memory-corruption issue in Microsoft Office file handling, and fixed two WebKit flaws involving node sets and text-node lifetime. Apple’s index dates the package to April 14, 2011.[2][3]

Source ledger

References

Sources are linked to the claims they support. Publication and access dates are shown when available.

  1. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · Certificate Trust Policy

    Back to text ↑
  2. Apple security updates (2011 to 2012)

    Apple Support · Apple · 2023-08-10T00:00:00.000Z · iOS 4.3.2 — 14 Apr 2011

    Back to text ↑
  3. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · libxslt, QuickLook, and WebKit entries

    Back to text ↑
  4. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · iOS 4.3.2 security content

  5. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · libxslt — CVE-2011-0195

  6. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · QuickLook — CVE-2011-1417

  7. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · WebKit — CVE-2011-1290

  8. About the security content of iOS 4.3.2 Software Update

    Apple Support · 2026-07-30 · WebKit — CVE-2011-1344

Release changes

Changed in this release

Features, fixes, removals, and regressions first observed in this release record.

security · fixed

Fraudulent certificate blocklist

documentedconfirmed

This reduced the ability of a privileged network attacker to redirect connections and intercept credentials or other sensitive data using those certificates.

  1. [1] About the security content of iOS 4.3.2 Software Update · Certificate Trust Policy