Live data from Hacker News

No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

joshua.hu

1–10 of 242 posts

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#4

When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

Yea, this reads like someone was denied a bounty for a "exploit" and decided to make it a whole thing as retribution.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#6

When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

And how's that more difficult than the loading page (exploit.svg) doing a GET/POST request to some server, after was loaded?

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#8

The iPhone 6S mentioned was released in 2015, but should run iOS 15, which Apple still should be releasing security updates for?

As he clearly describes in the article, Apple seems to patch some exploits but not others in older versions of iOS.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#9
post #7

This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry

Correct. The issue is it is not commonly known that Apple isn't actually backporting fixes for exploits while it has been claiming to update the phones: this is earth-shaking[^1] news

[^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Android itself for 7 years. I am sure significant decisions were made assuming this was the case.

Re: No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability

#10

When opening the page, your /etc/passwd is there for the world to see. ...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

Yea, this reads like someone was denied a bounty for a "exploit" and decided to make it a whole thing as retribution.

Yes, science as a public service as retribution
Post reply on HN