Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
Zerodium is interesting. Apparently this bug would fetch "Up to $50k": https://zerodium.com/images/zerodium_prices.png Is there a way to verify whether Zerodium might be advertising large payouts (for attention) and then offering much smaller payouts for the actual bugs? It's pretty risky for Zerodium. There's nothing stopping a researcher from collecting a payout and then reporting the bug to the vendor.
Zero click vulnerability in Apple’s macOS Mail
101–110 of 269 posts
Re: Zero click vulnerability in Apple’s macOS Mail
#102Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
and tbh, it's probably the same answer for most providers these days.
Re: Zero click vulnerability in Apple’s macOS Mail
#103For all those people who are complaining that Apple is taking its time paying out a bounty, and suggesting Zerodium: The end result of selling 0-click RCE vectors like this to brokers is sliced up bodies in embassies. Do folks think where the money coming from, and who would pay? No, its an 'easy' pay day. Some of us fix security bugs to keep people safe. Some of us try to earn an honest living doing so. Others try t…
Re: Zero click vulnerability in Apple’s macOS Mail
#104It seems backwards that Apple acknowledges the issue, PATCHES it, but still hasn't paid out. Maybe a good business is bug escrow company.
From wikipedia:
> Factoring is a financial transaction and a type of debtor finance in which a business sells its accounts receivable (i.e., invoices) to a third party (called a factor) at a discount.[1][2][3] A business will sometimes factor its receivable assets to meet its present and immediate cash needs.[4][5] Forfaiting is a factoring arrangement used in international trade finance by exporters who wish to sell their receivables to a forfaiter.[6] Factoring is commonly referred to as accounts receivable factoring, invoice factoring, and sometimes accounts receivable financing. Accounts receivable financing is a term more accurately used to describe a form of asset based lending against accounts receivable. The Commercial Finance Association is the leading trade association of the asset-based lending and factoring industries.[7]
Re: Zero click vulnerability in Apple’s macOS Mail
#105Earlier quoted context omitted.
There is literally no other detail than the phone model name. For all we know it could be an ancient iPhone with a severely outdated OS and a brand new Pixel phone. 4-digit passcode hasn't been the default passcode option in iOS for a long time.
https://www.tomsguide.com/news/police-say-android-phones-are... >This is supported by a look at smartphone cracking company Cellebrite’s effectiveness at breaking into different phones. Cellebrite can easily open up any iPhone X or earlier iPhone, but the same software used on a Google Pixel 2 or Galaxy S9 extracts very little information, and nothing at all in the case of the Huawei P20 Pro. >That’s not to say that…
Re: Zero click vulnerability in Apple’s macOS Mail
#106It's hardly surprising, you can run into memory corruption bugs just using desktop mail.app the way it's intended (there's been a bug that corrupts the account list for probably a decade which just hasn't been fixed.) Mutt may look old but at least it actually works.
This is a case of the application working as designed, but in unintended ways. A logic flaw.
I say this because I don't see a lot of effort being put into solving these types of security issues, compared to e.g. memory safety issues.
Re: Zero click vulnerability in Apple’s macOS Mail
#107Ok, remind me never to approach Apple directly if I happen to find a vulnerability. Zerodium (or a 3-letter agency) it is!
Re: Zero click vulnerability in Apple’s macOS Mail
#108Is it true that Apple devices are more secure than good Android devices(like Google's Pixel)? Or is it just security theater ?
As you can see, the price is so low it hardly even matters if there is a difference. There are literally millions of people in the US alone who personally have the liquid net worth to purchase a remote wormable persistent compromise that you can use to mass infect any Android or iPhone. Essentially every business with more than maybe 10 employees has enough assets to purchase such a weapon on the market. Just today I read on HN that the US government inked a deal for $22B over 10 years for 120k AR headsets from Microsoft [5] which comes out to ~$183k/headset. So, a weapon you can use to fully compromise any phone you want is equal in cost to a mere 15(!) headsets. That contract alone would be enough to purchase 10,000(!) vulnerabilities at existing clearing prices and $22B is only ~1/200th of the yearly US government budget.
Frankly, the entire thing is like two people jumping and comparing who is closer to landing on the moon.
[1] https://www.google.com/about/appsecurity/android-rewards/
[2] https://developer.apple.com/security-bounty/
[3] https://zerodium.com/program.html See Mobiles payout.
[4] https://www.statista.com/statistics/276306/global-apple-ipho....
[5] https://techcrunch.com/2021/03/31/microsoft-wins-contract-wo...
Re: Zero click vulnerability in Apple’s macOS Mail
#109It's hardly surprising, you can run into memory corruption bugs just using desktop mail.app the way it's intended (there's been a bug that corrupts the account list for probably a decade which just hasn't been fixed.) Mutt may look old but at least it actually works.
Re: Zero click vulnerability in Apple’s macOS Mail
#110> Mail will parse it to find out any attachments with x-mac-auto-archive=yes header in place. Mail will uncompress those files automatically. What could possibly go wrong? ;-/
This is the same exact issue that used to plague Outlook back in the day with the automatic handling of attachments. You'd think Apple would have learned from others' mistakes.
Why would you think that?