SSL Bugs Likely to Have Insurance Coverage Implications
Time 2 Minute Read

Hunton & Williams Insurance Litigation & Counseling partner Lon Berk reports:

The recently publicized Secure Sockets Layer (“SSL”) bug affecting Apple Inc. products raises a question regarding insurance coverage that is likely to become increasingly relevant as “The Internet of Things” expands. Specifically, on certain devices, the code used to set SSL connections contains an extra line that causes the program to skip a critical verification step. Consequently, unless a security patch is downloaded, when these devices are used on shared wireless networks they are subject to so-called “man-in-the-middle” security attacks and other serious security risks. Assuming that sellers of such devices may be held liable for damages, there may be questions about insurance to cover the risks.

Traditionally, products liability coverage is found in general liability policies. These policies, however, often contain exclusions cited by insurers to deny coverage for injuries relating to coding errors. One such exclusion bars coverage for damage to “impaired property” – essentially, property that has not sustained physical damage, but has been harmed by the insured’s work. Although at least one court has held that this exclusion precludes coverage for products that fail to function as intended due to coding errors, another court found the exclusion unintelligible and refused to enforce it.

A second exclusion often cited to restrict coverage is the “professional services” exclusion. Insurers may take the position that software engineering constitutes a “professional service” and, accordingly, liability caused by coding errors is not covered by their policies. Certain courts have accepted this interpretation notwithstanding the fact that it effectively renders products liability coverage illusory.

As The Internet of Things expands, an increasing number of everyday products will feature software components that may be susceptible to errors similar to the latest SSL bug. Accordingly, manufacturers should work with their insurance consultants to ensure that they are protected against all liabilities, including those arising out of coding errors in the devices and products they are developing.

You May Also Be Interested In

Time 2 Minute Read

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit held that the 2024 amendment to Illinois’ Biometric Information Privacy Act, limiting damages, applies retroactively to pending cases.

Time 1 Minute Read

If recent years have taught insurance practitioners anything, it is that the most consequential coverage disputes rarely turn on novelty alone. In 2025, courts continued to resolve high‑stakes insurance disputes by returning to first principles—examining when claims are related, how losses and occurrences are defined and aggregated, and how policy language allocates risk across time and conduct. D&O coverage and other core insurance law issues again occupied center stage, while decisions in property, cyber, and liability disputes reinforced a familiar theme: policy interpretation remains the decisive factor in determining whether coverage is available in an increasingly complex claims environment. As the decisions discussed below demonstrate, 2025 confirmed that even as risks evolve, coverage disputes remain grounded in careful, policy‑specific analysis.

Time 3 Minute Read

On September 12, 2025, the majority of the provisions of the EU Data Act began to apply across EU Member States. The Data Act was formally adopted in November 2023 and entered into force on January 11, 2024.

Time 2 Minute Read

On June 16, 2025, the UK Information Commissioner’s Office published its draft guidance on Internet of Things products and services.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page