Researcher details a WebKit flaw, which can lead to a RCE exploit, that remains unpatched by Apple despite the availability of an open source fix for 3 weeks
WebKit bug that was fixed upstream has yet to find its way into Apple products. — Apple has yet to patch a security bug found … Source: Theori .
A few weeks ago, we found an exploitable bug in WebKit which was fixed before we could report to Apple. Interestingly, the latest iOS versions are still vulnerable. Since other exploits for this bug are public, we share our root cause analysis and exploit. https://blog.theori.io/…
This exploit was a fun challenge. We didn't expect Safari to still be vulnerable weeks after the patch was public, but here we are... https://twitter.com/...
Three weeks is not that long, tbh, since Chrome used to have a patch gap of 6 weeks a few years back. I'm not even gonna touch the IoT field, where some patch gaps could be eligible for a driver's license. https://twitter.com/...