in Links

Apple releases iOS 7.0.6 fixing a serious SSL/TLS vulnerability

Information regarding the vulnerability is currently terribly scarce, but judging by the information in the Apple KB, it sounds very serious indeed and would allow man-in-the-middle attacks on SSL/TLS connections.

The problem was apparently found by Roland Moriz when trying to use curl on Mac OS, where it failed to identify a simple Common Name mismatch. (email proof)

What this means in reality is that someone who sits between you and a target site, such as your bank or Facebook, would be able to listen in on your traffic and potentially modify information as it is being sent to the server.