Legacy TLS Versions Enabled in Apple Networking Configurations

Legacy TLS versions enabled in Apple networking configurations

Description

Setting TLS 1.0 or TLS 1.1 as the minimum version in Foundation's URLSessionConfiguration or Security framework protocol options allows negotiation of those versions with legacy peers. Setting either as the maximum prevents TLS 1.2 and TLS 1.3 from being used.

RFC 8996, part of IETF BCP 195, prohibits TLS 1.0 and TLS 1.1. These versions lack support for modern recommended cipher suites and AEAD and rely on SHA-1-based mechanisms for handshake integrity or peer authentication. A low configured minimum alone does not establish that a connection actually used an obsolete version or that an attacker forced a downgrade. Check the server's supported versions and the actual network path as well.

Apple platform defaults

  • Apple deprecated TLS 1.0 and TLS 1.1 starting with iOS 15, iPadOS 15, macOS 12, watchOS 8, and tvOS 15.
  • For apps linked on or after iOS 26 or macOS 26, the default minimum TLS version in URLSession and the Network framework changed from 1.0 to 1.2.
  • URLSession connections covered by App Transport Security (ATS) require server support for TLS 1.2 or later by default. ATS exceptions can weaken this protection.
  • Apple's 2026 Platform Security documentation states that the operating systems also support TLS 1.0 and TLS 1.1. Explicit legacy settings and apps linked against earlier environments therefore still need attention on current operating systems.

Do not assume identical defaults across all Apple platforms. Review the app's link target, minimum deployment version, ATS exceptions, and networking APIs together.

Potential impact

  • Connections to legacy peers may use the outdated cryptographic features of TLS 1.0 or 1.1, weakening protection.
  • A maximum of TLS 1.0 or 1.1 can prevent connections to modern-only servers or prolong dependence on obsolete servers.
  • The configuration may fail to meet organizational or compliance requirements for TLS 1.2 or later.

Remediation

  1. Remove TLS 1.0/1.1 settings or set the minimum to tls_protocol_version_t.TLSv12. Prefer TLS 1.3 when all required peers support it.
  2. Do not cap the maximum below TLS 1.2. Unless interoperability requires a limit, leave it unset so newer versions can be negotiated.
  3. In new code, use tlsMinimumSupportedProtocolVersion and sec_protocol_options_set_min_tls_protocol_version, rather than deprecated SSLProtocol properties or sec_protocol_options_set_tls_min_version.
  4. Update legacy peers or isolate them on dedicated connections instead of weakening the application's overall policy. Record an owner, expiry date, and permitted destinations for exceptions.
  5. Test deployed clients and servers together to confirm that actual endpoints negotiate only TLS 1.2 or TLS 1.3.

Examples

Before

swift
import Foundation
import Security
import class Foundation.URLSessionConfiguration

func configureLegacyTLS(
    _ configuration: Foundation.URLSessionConfiguration
) {
    configuration.tlsMinimumSupportedProtocolVersion = .TLSv10
    configuration.tlsMaximumSupportedProtocolVersion = .TLSv11
}

The minimum permits TLS 1.0 and the maximum caps negotiation at TLS 1.1, so this configuration cannot negotiate TLS 1.2 or TLS 1.3.

After

URLSession

swift
import Foundation
import Security

let configuration = URLSessionConfiguration.default
configuration.tlsMinimumSupportedProtocolVersion = .TLSv12
// Leave the maximum unset to allow newer versions such as TLS 1.3.
let session = URLSession(configuration: configuration)

Network framework

swift
import Network
import Security

let tlsOptions = NWProtocolTLS.Options()
sec_protocol_options_set_min_tls_protocol_version(
    tlsOptions.securityProtocolOptions,
    .TLSv12
)
let parameters = NWParameters(tls: tlsOptions)

A compatible minimum of TLS 1.2 and an unrestricted maximum allow TLS 1.3 when the peer supports it. Retain certificate-chain and hostname verification independently of the version policy.

References