IOHIDeous OS X Local Kernel Vulnerability
siguza.github.io
IOHIDeous OS X Local Kernel Vulnerability
1–10 of 121 posts
Re: IOHIDeous OS X Local Kernel Vulnerability
#2Re: IOHIDeous OS X Local Kernel Vulnerability
#3First, the skills and persistence to get all these moving parts going. This must have been weeks of tiring work and exploration.
Second, the fact that the author wrote an incredibly detailed posting with a lot of detail and background information.
Wonderful work.
Re: IOHIDeous OS X Local Kernel Vulnerability
#4Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
Re: IOHIDeous OS X Local Kernel Vulnerability
#5Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
Re: IOHIDeous OS X Local Kernel Vulnerability
#6Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
Re: IOHIDeous OS X Local Kernel Vulnerability
#7Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
Re: IOHIDeous OS X Local Kernel Vulnerability
#8Re: IOHIDeous OS X Local Kernel Vulnerability
#9Re: IOHIDeous OS X Local Kernel Vulnerability
#10Responsible disclosure would have been to product-security@apple.com. Do apple have a bug-bounty program?
The term you're looking for is "Coordinated Disclosure". Yes, Coordinated Disclosure would involve sending the bug to Apple and waiting for them to publish it.
If you'd like to complain that this disclosure is irresponsible, fine. But try not to do it using the vendor's marketing term, because it's not up to them to decide what is and isn't "responsible". Other reasonable people --- myself included --- will probably disagree with you, and say that getting information out to people as comprehensively as possible is usually the most responsible thing you can do with a security bug.