Researchers discover “FREAK” flaw in Google and Apple devices that cripples HTTPS protection and enables man-in-the-middle attacks
Craig Timberg / Washington Post :
Context & Ripple Effects
The FREAK disclosure lands two months after researchers showed that vulnerabilities in the SS7 telephony protocol can decrypt cell calls and texts, extending a 2015 pattern in which the encryption protecting everyday communications keeps proving weaker than assumed. What makes this one different is scale and vendor breadth: it is not a single app or service but the HTTPS layer itself, on devices from both Apple and Google.
First-order effects
- Apple, Google, and Microsoft are all exposed — within days the bug was shown not limited to mobile, with coverage confirming the flaw affects Windows as well, forcing patches across every major platform at once.
- Users of unpatched Android and iOS devices are directly vulnerable to man-in-the-middle attacks that downgrade HTTPS connections, with follow-up reporting showing the exploit reaches thousands of individual Android and iOS apps, not just browsers.
Second-order effects
- App developers inherit the problem through shared crypto libraries, and the exposure compounds over time — weeks after disclosure, researchers counted roughly 25,000 iOS apps still open to eavesdropping, turning a platform patch into an ecosystem-wide audit.
- Enterprise security teams must treat TLS configurations as attack surface in their own right, pressuring vendors to strip weak cipher suites rather than ship them enabled by default.
Third-order effects
- If the pattern holds — SS7, then FREAK, then the later Safari address-spoofing bug and the 2020 zero-click AWDL exploit — the industry's assumption that transport encryption guarantees confidentiality erodes structurally, shifting scrutiny toward legacy crypto inherited from old export rules and toward regulator interest in mandated minimum cryptographic standards.
The trend: Encryption is being re-examined end to end in 2015, as researchers repeatedly show that long-standing protocol and cipher defaults — HTTPS cipher suites here, telephony signaling before it — leave mainstream devices open to interception.