Apple 'goto fail' (2014)
A duplicated line of code in Apple's TLS implementation disabled certificate verification in iOS and macOS. The bug let attackers intercept supposedly secure connections, including email and banking traffic. Apple shipped a fix within days.
Apple released iOS 7.0.6 and OS X 10.9.2 to patch the flaw within days of discovery.
The bug became a case study in how a single line of code can break TLS verification, and in the importance of code review for security-critical paths.
Like the Xray-core flaw, 'goto fail' was a certificate verification bypass that enabled man-in-the-middle attacks. The difference is that Apple disclosed it publicly, while Xray-core's fix shipped silently.
