Tag Archive for: ios

Apple fails to patch publicly disclosed zero-day flaws with iOS 15.0.1


Apple’s latest point update for iOS 15 does not contain patches for three zero-day vulnerabilities that were reported to the company months ago and publicly disclosed last week.

iPhone 13 mini

In September, security researcher Denis Tokarev, better known by his pseudonym illusionofcha0s, claimed that Apple ignored multiple reports pertaining to newly discovered zero-day vulnerabilities present in iOS, the company’s flagship mobile operating system. Tokarev reported four flaws to Apple between March 10 and May 4, and while one issue was patched in iOS 14.7, the other three remain active in the latest iOS 15.0.1.

By his own admission, the zero-day vulnerabilities that persist are not critical, with one pertaining to a bug that could enable maliciously crafted apps to read users’ Apple ID information if somehow allowed onto the App Store.

Still, Apple’s handling of the disclosures, reported through the Bug Bounty Program, does not sit well with Tokarev, who penned a blog post in late September detailing his interactions with tech giant’s team. According to the researcher, Apple failed to list the security issue it patched in iOS 14.7 and did not add information about the flaw in subsequent security page updates.

“When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update,” illusionofchaos wrote at the time. “There were three releases since then and they broke their promise each time.”

Apple saw Tokarev’s blog post and again apologized. The company said its teams were still investigating the three remaining vulnerabilities as of Sept. 27, but Tokarev made the flaws public last week in line with standard vulnerability disclosure protocols.

Ethical hackers have criticized Apple’s Bug Bounty Program and the company’s general handling of public security researchers, citing a lack of communication, payment issues and other problems. The initiative offers payouts for bugs and exploits.

Earlier this week, researcher Bobby Rauch publicly disclosed an AirTag vulnerability after Apple failed to answer basic questions about the bug and whether Rauch would be credited with the find. The…

Source…

Researcher Details Three Zero-Day Exploits Still Present In iOS 15


Usually software updates come with things like bug fixes and security patches. Unfortunately for iOS 15, it seems that Apple has left in three zero-day exploits despite being warned in advance. This is according to a post by an anonymous security researcher and shared and verified by Kosta Eleftheriou.

According to the post, “I’ve reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page.” 

They add, “When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time.” 

The researcher then gave Apple the courtesy by giving them an opportunity to respond and provide an explanation, if not they would make the information public, which obviously they haven’t which is why those vulnerabilities have since been disclosed.

These vulnerabilities are a bit technical but they are explained on the researcher’s blog, so if you’re curious to learn more you can check it out. Apple has yet to respond to the post, but given that these exploits have been made public and are potentially exploitable by hackers who now know about them, hopefully they’ll be patching them ASAP.

Filed in Apple >Cellphones. Read more about iOS, Ios 15 and Security. Source: macrumors

Source…

Tech Trends: Mobile Security with Steve Phillips and Andrew Hoog



How to Install Bitdefender Total Security to All Your Devices With NETGEAR Armor