About the security content of Security Update 2018-001
support.apple.com
About the security content of Security Update 2018-001
1–10 of 18 posts
Re: About the security content of Security Update 2018-001
#2https://security.googleblog.com/2014/07/announcing-project-z...
Re: About the security content of Security Update 2018-001
#3Re: About the security content of Security Update 2018-001
#4Re: About the security content of Security Update 2018-001
#5What is with this title ? It's a result of two CVEs.
Re: About the security content of Security Update 2018-001
#6What is with this title ? It's a result of two CVEs.
Re: About the security content of Security Update 2018-001
#7For anyone unfamiliar with Project Zero, it's a team at Google dedicated to finding security vulnerabilities across the internet (and in software in general, it seems) https://security.googleblog.com/2014/07/announcing-project-z...
- SHAttered(?)
- Row hammer
- Cloudbleed
- Lastpass exploit
- Meltdown & Spectre
Re: About the security content of Security Update 2018-001
#8What is with this title ? It's a result of two CVEs.
In the support article Apple is crediting one of the CVEs “CVE-2018-4206: Ian Beer of Google Project Zero”
Furthermore, Project Zero was involved in only one of the CVEs anyway then. Why not put the other credit in the title too? CVE-2018-4187: Zhiyang Zeng (@Wester) of Tencent Security Platform Department, Roman Mueller (@faker_)