iOS 15.0.2 official version fixes a zero-day vulnerability, but no thanks to security researchers

Publisher:NatureLoverLatest update time:2021-10-15 Source: IT之家Keywords:iOS Reading articles on mobile phones Scan QR code
Read articles on your mobile phone anytime, anywhere

      According to 9to5 Mac, last month, security researcher Denis Tokarev (aka illusionofchaos) shared his experience of reporting three zero-day iOS vulnerabilities to Apple and criticized how Apple was slow to respond, slow to act, and did not patch one of the three reported vulnerabilities in a timely manner. Now it seems that Apple has fixed one of the zero-day vulnerabilities, which was a vulnerability in the iOS 15 system discovered by Denis Tokarev earlier this year, but Apple did not give him a credit or thank him.


  In September, Tokarev said that after waiting for as long as half a year to report some vulnerabilities to Apple, he decided to make the information public.

  "Ten days ago I asked for an explanation and warned at the time that if I didn't get one, the research would be made public. My request was ignored, so I am doing what I said. My actions are in line with responsible disclosure guidelines (Google Project Zero discloses vulnerabilities within 90 days of reporting to the vendor ZDI). I have waited longer, in one case up to half a year."

  In late September, Tokarev shared that he got a response from Apple saying they were still working on the "issues" and apologized for the delays.

  In his September blog post, Tokarev detailed a manipulated zero-day vulnerability (1 of 3) that would have allowed any app installed from the App Store to obtain personal user data such as Apple ID email and full name, Apple ID authorization tokens, full file system read access to the Core Duet database, and more.

  Now Tokarev says he has discovered that Apple has patched the gaming zero-day vulnerability he discovered in the iOS 15.0.2 security update, but has not credited him.

  When the first zero-day vulnerability that Tokarev discovered and reported to Apple was fixed in the official version of iOS 14.7 (July 19), he did not receive a reward, Apple told him.

  "Due to processing issues, your reward will be included as a security advisory in an upcoming update. We apologize for the inconvenience."

  After patching the second vulnerability in iOS 15.0.2 and attributing it to "an anonymous researcher," Tokarev says Apple did respond to him within six hours, but apparently there was no way to fix the problem of citing him correctly. Meanwhile, Apple still hasn't responded to the compensation for the analyticsd zero-day vulnerability he discovered that was patched in iOS 14.7.

  Tokarev was asked to keep Apple's latest emails confidential, and he has complied with that request for now.


Keywords:iOS Reference address:iOS 15.0.2 official version fixes a zero-day vulnerability, but no thanks to security researchers

Previous article:Xiaomi Mi 11 series pushes MIUI 12.5.13.0 stable version: updates Google September security patch
Next article:Apple Music app is expected to be launched on Sony PS5, players have already seen the icon appear

Latest Mobile phone portable Articles
Change More Related Popular Components

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号