iTunes 10.5.1 Includes Minor Security Update
Posted on by Peter James
Apple has released iTunes 10.5.1, the latest version of the company’s media management software, which notably includes the company’s new iTunes Match cloud music service. This update contains one minor security fix, described as follows:
Impact: A man-in-the-middle attacker may offer software that appears to originate from Apple
Description: iTunes periodically checks for software updates using an HTTP request to Apple. This request may cause iTunes to indicate that an update is available. If Apple Software Update for Windows is not installed, clicking the Download iTunes button may open the URL from the HTTP response in the user’s default browser. This issue has been mitigated by using a secured connection when checking for available updates. For OS X systems, the user’s default browser is not used because Apple Software Update is included with OS X, however this change adds additional defense-in-depth.
As the description points out, this isn’t a serious issue for Mac users, but Apple is fixing it for them anyway, as there’s always the possibility that someone could create a fake program that looks like Apple’s Software Update.
You can download this new version of iTunes from, of course, Software Update, or from Apple’s iTunes download page.