Researcher discloses three iOS zero-days, says they were reported to Apple before May 4 and are still exploitable in iOS 15 after Apple failed to fix them
The disclosure follows a recurring iOS zero-day pattern: Apple had patched three flaws in iOS 14.4 after reports they may have been exploited, while earlier research identified actively exploited flaws that had persisted since iOS 6. The new report matters because the researcher says Apple received it before May 4, yet all three flaws remained exploitable in iOS 15.
Apple has previously issued a patch after iOS flaws were linked to attempts to remotely take activists’ data, as in the iOS 9.3.5 security update. That history makes the reported gap between notification and remediation consequential for users on the current release.
First-order effects
Apple faces an urgent remediation task for three reported vulnerabilities that the researcher says persist in iOS 15.
iOS 15 users remain exposed to the disclosed flaws until Apple ships fixes or otherwise mitigates them.
Second-order effects
The unpatched report puts pressure on Apple’s vulnerability-handling process, particularly its ability to move researcher submissions into fixes before a major iOS release.
Security researchers and organizations supporting at-risk users gain another reason to evaluate iOS patch status as part of device-risk management rather than treating a current OS version as sufficient assurance.
Third-order effects
Repeated disclosures across iOS generations point to platform security becoming increasingly shaped by the speed and transparency of vendor response after credible reports, not just by the number of patches released.
If delayed fixes continue to surface after public disclosure, researchers’ reporting practices and proof attached to reports may carry more weight in holding platform vendors accountable for remediation timelines.
The trend: Mobile-platform security is moving toward greater scrutiny of the interval between zero-day reporting, disclosure, and vendor remediation.
🚨Apple ignored this person. Now they're publishing multiple proofs-of-concepts: “I've reported four 0-day vulnerabilities this year [...], three of them are still present in [iOS 15.0] and one was fixed in 14.7, but Apple decided to cover it up”🤯 https://habr.com/...
It appears to be able to pull my entire contact list and lots of details about my conversations, with no user prompt of any kind. I see a ton of my own private data in each of these 3 sections: https://twitter.com/...
“I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page” 😮
https://habr.com/... 3 iOS 0days dropped. Also, what the fuck is Apple doing with this info!? Why do they need to log your menstrual cycles? https://twitter.com/...
The report shows any app could access contact details without requesting permission. That's what Apple just decided to sweep under the rug. https://habr.com/... via https://news.ycombinator.com/ ...
Why is Apple not working with security researchers who are finding highly critical bugs like these? They should put someone competent in charge to run a proper security bounty program. It is just so bizarre that this is completely mismanaged. https://habr.com/...