/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher discloses three iOS zero-days, says they were reported to Apple before May 4 and are still exploitable in iOS 15 after Apple failed to fix them

Information Security *Development for iOS *Development of mobile applications *Reverse engineering *

Habr Illusionofchaos

Context & Ripple Effects

The disclosure follows a recurring iOS zero-day pattern: Apple had patched three flaws in iOS 14.4 after reports they may have been exploited, while earlier research identified actively exploited flaws that had persisted since iOS 6. The new report matters because the researcher says Apple received it before May 4, yet all three flaws remained exploitable in iOS 15.

Apple has previously issued a patch after iOS flaws were linked to attempts to remotely take activists’ data, as in the iOS 9.3.5 security update. That history makes the reported gap between notification and remediation consequential for users on the current release.

First-order effects

  • Apple faces an urgent remediation task for three reported vulnerabilities that the researcher says persist in iOS 15.
  • iOS 15 users remain exposed to the disclosed flaws until Apple ships fixes or otherwise mitigates them.

Second-order effects

  • The unpatched report puts pressure on Apple’s vulnerability-handling process, particularly its ability to move researcher submissions into fixes before a major iOS release.
  • Security researchers and organizations supporting at-risk users gain another reason to evaluate iOS patch status as part of device-risk management rather than treating a current OS version as sufficient assurance.

Third-order effects

  • Repeated disclosures across iOS generations point to platform security becoming increasingly shaped by the speed and transparency of vendor response after credible reports, not just by the number of patches released.
  • If delayed fixes continue to surface after public disclosure, researchers’ reporting practices and proof attached to reports may carry more weight in holding platform vendors accountable for remediation timelines.

The trend: Mobile-platform security is moving toward greater scrutiny of the interval between zero-day reporting, disclosure, and vendor remediation.

Discussion

  • @keleftheriou Kosta Eleftheriou on x
    🚨Apple ignored this person. Now they're publishing multiple proofs-of-concepts: “I've reported four 0-day vulnerabilities this year [...], three of them are still present in [iOS 15.0] and one was fixed in 14.7, but Apple decided to cover it up”🤯 https://habr.com/...
  • @keleftheriou Kosta Eleftheriou on x
    It appears to be able to pull my entire contact list and lots of details about my conversations, with no user prompt of any kind. I see a ton of my own private data in each of these 3 sections: https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    Can confirm the exploit runs successfully on iOS 14.8: https://twitter.com/...
  • @alex @alex on x
    not fun to watch iOS start to feel more like Windows XP before SP1 https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    🚨Can confirm the exploit also works on iOS 15.0 - it's able to silently pull a *trove* of personal information without _any_ kind of user prompt.
  • @mahemoff @mahemoff on x
    “I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page” 😮
  • @renakunisaki @renakunisaki on x
    https://habr.com/... 3 iOS 0days dropped. Also, what the fuck is Apple doing with this info!? Why do they need to log your menstrual cycles? https://twitter.com/...
  • @mahemoff @mahemoff on x
    The report shows any app could access contact details without requesting permission. That's what Apple just decided to sweep under the rug. https://habr.com/... via https://news.ycombinator.com/ ...
  • @satefan Stefan Arentz on x
    Why is Apple not working with security researchers who are finding highly critical bugs like these? They should put someone competent in charge to run a proper security bounty program. It is just so bizarre that this is completely mismanaged. https://habr.com/...