Apple 'still investigating' three unpatched security flaws in iOS 15

Apple 'still investigating' three unpatched security flaws in iOS 15

In early September, security researcher Denis Tokarev wrote a blog post in which he complained about some interactions with Apple's bug bounty program. The incident originated from four security vulnerabilities submitted to Apple through the Bug Nounty Program. However, after waiting for a long time, he found that only one had been fixed. The latest news is that Apple has responded to the matter, claiming that it is "still investigating" the relevant issues.

[[426391]]

Tokarev told Motherboard that three other vulnerabilities were not fixed in the earlier iOS 15 update. Now, Apple has apologized for the delay in communication and added that the company is investigating the issues.

We have seen your blog post and other reports of this issue and apologize for the late response. We want to let you know that we are still investigating these issues and how we are fixing them to protect customers.

Thanks again for taking the time to report these issues to us, and please let us know if we can help you in any way.

However, aside from the three buildings that Apple is still fixing, Tokarev said he was not credited for reporting the fixed vulnerability.

It is reported that the three unpatched vulnerabilities include a flaw that may cause the App Store application to read certain data including Apple ID, email address, contact list, etc.

However, Tokarev also admitted that the three vulnerabilities he reported between March 10 and May 4, 2021 were not that serious, so it is understandable to a certain extent that Apple did not give them such a high priority.

Finally, despite Apple's claim that its bug bounty program has been "hugely successful," at least one cybersecurity expert told Motherboard that Apple's handling of this situation is somewhat unusual.

Another said that it wasn't until the media exposed the loopholes in the repair department that Apple took the time to respond to Tokarev's questions.

<<:  WeChat cloud storage charges kill three birds with one stone, but it is "going against the trend"

>>:  WeChat iOS version updated! Voice calls can display the other party's Moments updates

Recommend

The core model and skills of community operation!

This year, the term " community operation &q...

New iPod touch performance test: Gaming performance increased dramatically

Last Wednesday, Apple quietly released a new iPod...

Marketing is sick, is there a cure for copywriting?

Many brands use low prices to increase product sa...

The whole process of product operation from 0 to 1

The main purpose of this article is to share my p...

Analysis of the most effective Taobao promotion methods for Taobao operations

Many sellers currently have a problem, that is, t...

Introduction to home decoration space design

Starting from the basics, we will understand the ...

Healing brand advertising becomes mainstream!

To be honest, in recent years, under the pressure...

If the APP is renamed well, there will be no loss of users!

1. Why did the App product change its name? For m...

Lunar Module: The two richest men in the world compete on the lunar surface

On May 19, 2023, NASA announced that it had selec...

Case review + fission methodology | Why is your fission activity ineffective?

I recently chatted with a fellow operations partn...

What can we ordinary people do when faced with sudden death?

Recently, the incident of a student from Shanxi U...