Title: Researcher Says Apple Ignored Three Zero-Day Security Vulnerabilities Still Present in iOS 15 Post by: HCK on September 27, 2021, 04:05:09 pm Researcher Says Apple Ignored Three Zero-Day Security Vulnerabilities Still Present in iOS 15
In 2019, Apple opened its Security Bounty Program to the public (https://www.macrumors.com/2019/12/20/apple-launches-public-bug-bounty-program/), offering payouts up to $1 million to researchers who share critical iOS, iPadOS, macOS, tvOS, or watchOS security vulnerabilities with Apple, including the techniques used to exploit them. The program is designed to help Apple keep its software platforms as safe as possible. (https://images.macrumors.com/article-new/2021/09/iPhone-13-Security.jpg) In the time since, reports have surfaced indicating that some security researchers are unhappy with the program (https://www.macrumors.com/2021/09/09/security-researchers-apple-bug-bounty-complaints/), and now a security researcher who uses the pseudonym "illusionofchaos" has shared their similarly "frustrating experience." In a blog post (https://habr.com/en/post/579714/) highlighted by Kosta Eleftheriou (https://twitter.com/keleftheriou/status/1441242689748410373), the unnamed security researcher said they reported four zero-day vulnerabilities to Apple between March and May of this year, but they said that three of the vulnerabilities are still present in iOS 15 and that one was fixed in iOS 14.7 without Apple giving them any credit. I want to share my frustrating experience participating in Apple Security Bounty program. I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page. When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time.The person said that, last week, they warned Apple that they would make their research public if they didn't receive a response. However, they said Apple ignored the request, leading them to publicly disclose the vulnerabilities. One of the zero-day vulnerabilities relates to Game Center and allegedly allows any app installed from the App Store to access some user data: - Apple ID email and full name associated with itThe other two zero-day vulnerabilities that are apparently still present in iOS 15, as well as the one patched in iOS 14.7, are also detailed in the blog post. <div class="center-wrap"><blockquote class="twitter-tweet"><p lang="en" dir="ltr">Click through to see the Game Center exploit in particular. It’s rough. Things like this should almost never slip through the cracks with a functioning security program. Instead, with Apple, it’s commonplace. That’s so deeply broken, yet nothing changes. What will it take?</p>— Marco Arment (@marcoarment) September 24, 2021 (https://twitter.com/marcoarment/status/1441394975883743235?ref_src=twsrc%5Etfw) <script async src="https://platform.twitter.com/widgets.js" charset="utf-8"></script></div>Apple has not yet commented on the blog post. We'll update this story if the company responds.<div class="linkback">Related Roundups: iOS 15 (https://www.macrumors.com/roundup/ios-15/), iPadOS 15 (https://www.macrumors.com/roundup/ipados-15/)</div><div class="linkback">Tag: Apple security (https://www.macrumors.com/guide/apple-security/)</div><div class="linkback">Related Forum: iOS 15 (https://forums.macrumors.com/forums/ios-15.233)</div> This article, "Researcher Says Apple Ignored Three Zero-Day Security Vulnerabilities Still Present in iOS 15 (https://www.macrumors.com/2021/09/24/ios-15-zero-day-vulnerabilities-report/)" first appeared on MacRumors.com (https://www.macrumors.com) Discuss this article (https://forums.macrumors.com/threads/researcher-says-apple-ignored-three-zero-day-security-vulnerabilities-still-present-in-ios-15.2313167/) in our forums <div class="feedflare"> <img src="http://feeds.feedburner.com/~ff/MacRumors-Front?d=yIl2AUoC8zA" border="0"></img> (http://feeds.macrumors.com/~ff/MacRumors-Front?a=8Rlre2JcW4s:FAZ3xqtGvmM:yIl2AUoC8zA) <img src="http://feeds.feedburner.com/~ff/MacRumors-Front?d=6W8y8wAjSf4" border="0"></img> (http://feeds.macrumors.com/~ff/MacRumors-Front?a=8Rlre2JcW4s:FAZ3xqtGvmM:6W8y8wAjSf4) <img src="http://feeds.feedburner.com/~ff/MacRumors-Front?d=qj6IDK7rITs" border="0"></img> (http://feeds.macrumors.com/~ff/MacRumors-Front?a=8Rlre2JcW4s:FAZ3xqtGvmM:qj6IDK7rITs) </div><img src="http://feeds.feedburner.com/~r/MacRumors-Front/~4/8Rlre2JcW4s" height="1" width="1" alt=""/> Source: Researcher Says Apple Ignored Three Zero-Day Security Vulnerabilities Still Present in iOS 15 (https://www.macrumors.com/2021/09/24/ios-15-zero-day-vulnerabilities-report/) |