No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
1–10 of 242 posts
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#2Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#3...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#4When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#5Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#6When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#7Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#8The iPhone 6S mentioned was released in 2015, but should run iOS 15, which Apple still should be releasing security updates for?
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#9This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry
[^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Android itself for 7 years. I am sure significant decisions were made assuming this was the case.
Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
#10When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.
Yea, this reads like someone was denied a bounty for a "exploit" and decided to make it a whole thing as retribution.