/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researcher discloses three iOS zero-days, says they were reported to Apple before May 4 and are still exploitable in iOS 15 after Apple failed to fix them

what you need to know Mahit Huilgol / iPhone Hacks : Apple Reportedly Fails to Patch Multiple iOS 15 Zero-Day Vulnerabilities First Reported in March Pierluigi Paganini / Security Affairs : Researcher released PoC exploit code for 3 iOS zero-day issues Mike Peterson / AppleInsider : Apple ignored reports of three big security problems in iOS 15, researcher says Stephen Warwick / iMore : Researcher warns of three zero-day iPhone hacks still not fixed Michael Potuck / 9to5Mac : Security researcher accuses Apple of ignoring multiple iOS 15 zero-day vulnerabilities Ravie Lakshmanan / The Hacker News : Urgent Apple iOS and macOS Updates Released to Fix Actively Exploited Zero-Days Tweets: Kosta Eleftheriou / @keleftheriou : 🚨Apple ignored this person. Now they're publishing multiple proofs-of-concepts: “I've reported four 0-day vulnerabilities this year [...], three of them are still present in [iOS 15.0] and one was fixed in 14.7, but Apple decided to cover it up”🤯 https://habr.com/... @0xa1ec : I hate seeing this, because I also sent two bug bounty reports to Apple the day iOS 13 beta was released, and never had resolution following months emails. “We are still working through the backlog. Just a reminder, if you publish your findings, we will not compensate you.” https://twitter.com/... Kosta Eleftheriou / @keleftheriou : 🚨"Any app installed from the App Store may access the following data without any prompt from the user:" https://twitter.com/... Corellium / @corelliumhq : Your security work shouldn't be held up for months waiting on unreliable public jailbreaks. Corellium users know they can depend on getting access to rooted versions of the latest devices and the latest OS's almost as soon as they're released. https://twitter.com/... Khaos Tian / @khaost : This is kinda bad given Core Duet tracks a lot of user activities on device. Maybe Apple's security team really believe that App Review will capture this 🙃 https://twitter.com/... https://twitter.com/... Kosta Eleftheriou / @keleftheriou : When Apple doesn't bother to fix serious issues long after they've been *reported* to them, how can we trust them to be the good stewards of an ecosystem used by a billion people? Rampant scams on the App Store are another example of Apple's failings: https://www.theverge.com/... Felix Krause / @krausefx : Apple's bug bounty program *needs* to improve, this is not okay. Three 0-day iOS vulnerabilities for unauthorized access to medical data, iMessage, third party messengers, device usage, ... > I still haven't received any reply so I publish this article https://habr.com/... Kosta Eleftheriou / @keleftheriou : 🚨Can confirm the exploit also works on iOS 15.0 - it's able to silently pull a *trove* of personal information without _any_ kind of user prompt. April King / @cubicleapril : What is going on over at @apple these days? Between constant reports of neglected vulnerabilities and broken security patches, the situation seems increasingly dire. Maybe they need to move to a public vuln reporting platform to have visible metrics? https://arstechnica.com/... Lesley Carhart / @hacks4pancakes : @msuiche It's okay. I'm pretty sure most will accept payment in iPhone 13 Pros Ashley M. Gjøvik / @ashleygjovik : @alanlangford_ca Oh my god 😭😭😭 Yup. Kosta Eleftheriou / @keleftheriou : UPDATE: Apple finally responds👇 https://twitter.com/... Joseph Menn / @josephmenn : There are few expressions of dismay with a bug bounty program, in this case Apple's, that are quite as clear as dumping proof-of-concept code for unpatched holes. https://www.bleepingcomputer.com/ ... Tobie Langel / @tobie : Apple, fix those 0-day issues and give this researcher the 6-figure bounties you owe them. https://twitter.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : Regardless of the potential danger of these exploits, this is a great example of Apple's problems when dealing with researchers who report bugs through its bug bounty program. https://www.vice.com/... Iza / @izmcm : @illusionofcha0s ... You are completely right! The Gamed PoC passed the automatic review Alex Russell / @slightlylate : The “Apple needs to ban other engines because security” thing is aggressively, self-consciously stupid. https://infrequently.org/... https://twitter.com/... Kosta Eleftheriou / @keleftheriou : 🚨The Game Center proof-of-concept exploit even passes automatic review: https://twitter.com/... Alex Russell / @slightlylate : If only they hadn't blown the whole budget on WebKit/Safari. https://twitter.com/... Laurie Voss / @seldo : I mean it's obviously not cool that Apple ignored a security researcher but “an app installed from the App store can access your personal information” does not seem like a smash-the-glass emergency to me. https://twitter.com/... Lance R. Vick / @lrvick : I found a DRM bypass in MacOS recently. Rather than cash it in with Apple, I gave it to a group actively working to undermine their walled gardens. Apple doesn't care about security, privacy, or freedom, so I don't care about them. Csaba Fitzl / @theevilbit : The most interesting thing about these 0days that I also reported the Core Duet privacy info leaks, but for macOS, long time ago. That was fixed. Apparently iOS was also vulnerable and Apple didn't realize it. Maybe I should start looking into iOS. 👀 https://habr.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : We just updated the story with comments from the researcher who found the bugs. https://www.vice.com/... https://twitter.com/... Alex Russell / @slightlylate : Every OS has security issues. What's important to understand here is how the approaches differ. Other OSes let you move your computing to a safer layer (the web) and deliver choice + competition about those protections. Only iOS keeps mobile down in the (security) dirt. https://twitter.com/... @alanlangford_ca : I presume fixing these exploits will make it harder for Apple to spy on its employees... cc @ashleygjovik https://twitter.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: A researcher has published the source code for exploits that take advantage of three unpatched iPhone bugs. Another researcher said he was able to reproduce exploits in 30 mins. But bugs are not *that* dangerous for users. https://www.vice.com/... @alex : not fun to watch iOS start to feel more like Windows XP before SP1 https://twitter.com/... Nicole Perlroth / @nicoleperlroth : It looks like Apple has a bug bounty problem. This researcher claims they've reported 4 zero days, 3 of which are still exploitable in iOS 15. This after a Spanish researcher dumped a lockscreen bypass because he says Apple ignored him. https://therecord.media/... https://twitter.com/... Catalin Cimpanu / @campuscodi : Nothing major like an RCE, hence the reason why Apple hasn't prioritized them (per someone familiar with Apple's bbp inner workings) https://twitter.com/... Marco Arment / @marcoarment : Click through to see the Game Center exploit in particular. It's rough. Things like this should almost never slip through the cracks with a functioning security program. Instead, with Apple, it's commonplace. That's so deeply broken, yet nothing changes. What will it take? Marco Arment / @marcoarment : Security relations are developer relations. What will it take for Apple to change their entire CULTURE of how they treat outside developers? https://twitter.com/... @msuiche : Rumors are saying that Apple can't afford to pay the maximum payouts on bug bounties and that's why they never did. I'm starting a fund raising to help Apple, reach out if you want to donate and assist Apple through that difficult period. SoS / @swiftonsecurity : But seriously how Apple doesn't just pay 100k for every bug is the dumbest penny pinching when you've got a trillion fucking dollars https://twitter.com/... Kosta Eleftheriou / @keleftheriou : Another researcher annoyed with how Apple handled his report, from just a few days ago: https://twitter.com/... Kosta Eleftheriou / @keleftheriou : Apple will never change their ways until they're publicly shamed. Sad to see it has come to this. Kosta Eleftheriou / @keleftheriou : It appears to be able to pull my entire contact list and lots of details about my conversations, with no user prompt of any kind. I see a ton of my own private data in each of these 3 sections: https://twitter.com/... Kosta Eleftheriou / @keleftheriou : The website at the top of the thread seems to be having some intermittent issues. Link to archived page: https://archive.is/... Kosta Eleftheriou / @keleftheriou : Can confirm the exploit runs successfully on iOS 14.8: https://twitter.com/... @mahemoff : “I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page” 😮 @mahemoff : The report shows any app could access contact details without requesting permission. That's what Apple just decided to sweep under the rug. https://habr.com/... via https://news.ycombinator.com/ ... @renakunisaki : https://habr.com/... 3 iOS 0days dropped. Also, what the fuck is Apple doing with this info!? Why do they need to log your menstrual cycles? https://twitter.com/... Stefan Arentz / @satefan : Why is Apple not working with security researchers who are finding highly critical bugs like these? They should put someone competent in charge to run a proper security bounty program. It is just so bizarre that this is completely mismanaged. https://habr.com/...

Habr Denis Tokarev

Context & Ripple Effects

The disclosure lands after Apple had already patched three iOS zero-days in iOS 14.4 following an anonymous tip, while earlier reporting described actively exploited iPhone flaws that had persisted across multiple iOS generations. The recurring issue is not merely vulnerability discovery, but the interval between a researcher’s report and Apple’s remediation.

First-order effects

  • iOS 15 users remain exposed to the three reported flaws while Apple has no reported fix, and the published proof-of-concept code makes the claims easier to scrutinize and reproduce.
  • Apple faces immediate pressure to triage and patch vulnerabilities it was reportedly told about before May 4.

Second-order effects

  • The public disclosure makes Apple’s response process directly comparable with its earlier iOS 14.4 zero-day patch cycle, raising the cost of leaving reported flaws unresolved.
  • Researchers reporting iOS flaws gain a concrete example of proof-of-concept publication being used to force attention after a reported vulnerability remains unpatched.

Third-order effects

  • If repeated zero-day disclosures continue to precede fixes, iOS security will be judged increasingly on Apple’s report-to-patch turnaround rather than on the size of individual software updates.
  • Publicly reproducible reports can shift vulnerability handling toward more accountable disclosure and remediation workflows, with platform vendors under pressure to show when reports are received and resolved.

The trend: Mobile-platform security is moving toward faster, more transparent zero-day remediation as researchers use public proof-of-concept disclosures to challenge slow patch cycles.

Discussion

  • @keleftheriou Kosta Eleftheriou on x
    🚨Apple ignored this person. Now they're publishing multiple proofs-of-concepts: “I've reported four 0-day vulnerabilities this year [...], three of them are still present in [iOS 15.0] and one was fixed in 14.7, but Apple decided to cover it up”🤯 https://habr.com/...
  • @keleftheriou Kosta Eleftheriou on x
    🚨"Any app installed from the App Store may access the following data without any prompt from the user:" https://twitter.com/...
  • @corelliumhq Corellium on x
    Your security work shouldn't be held up for months waiting on unreliable public jailbreaks. Corellium users know they can depend on getting access to rooted versions of the latest devices and the latest OS's almost as soon as they're released. https://twitter.com/...
  • @khaost Khaos Tian on x
    This is kinda bad given Core Duet tracks a lot of user activities on device. Maybe Apple's security team really believe that App Review will capture this 🙃 https://twitter.com/... https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    When Apple doesn't bother to fix serious issues long after they've been *reported* to them, how can we trust them to be the good stewards of an ecosystem used by a billion people? Rampant scams on the App Store are another example of Apple's failings: https://www.theverge.com/...
  • @krausefx Felix Krause on x
    Apple's bug bounty program *needs* to improve, this is not okay. Three 0-day iOS vulnerabilities for unauthorized access to medical data, iMessage, third party messengers, device usage, ... > I still haven't received any reply so I publish this article https://habr.com/...
  • @keleftheriou Kosta Eleftheriou on x
    🚨Can confirm the exploit also works on iOS 15.0 - it's able to silently pull a *trove* of personal information without _any_ kind of user prompt.
  • @cubicleapril April King on x
    What is going on over at @apple these days? Between constant reports of neglected vulnerabilities and broken security patches, the situation seems increasingly dire. Maybe they need to move to a public vuln reporting platform to have visible metrics? https://arstechnica.com/...
  • @hacks4pancakes Lesley Carhart on x
    @msuiche It's okay. I'm pretty sure most will accept payment in iPhone 13 Pros
  • @ashleygjovik Ashley M. Gjøvik on x
    @alanlangford_ca Oh my god 😭😭😭 Yup.
  • @keleftheriou Kosta Eleftheriou on x
    UPDATE: Apple finally responds👇 https://twitter.com/...
  • @josephmenn Joseph Menn on x
    There are few expressions of dismay with a bug bounty program, in this case Apple's, that are quite as clear as dumping proof-of-concept code for unpatched holes. https://www.bleepingcomputer.com/ ...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    Regardless of the potential danger of these exploits, this is a great example of Apple's problems when dealing with researchers who report bugs through its bug bounty program. https://www.vice.com/...
  • @izmcm Iza on x
    @illusionofcha0s ... You are completely right! The Gamed PoC passed the automatic review
  • @slightlylate Alex Russell on x
    The “Apple needs to ban other engines because security” thing is aggressively, self-consciously stupid. https://infrequently.org/... https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    🚨The Game Center proof-of-concept exploit even passes automatic review: https://twitter.com/...
  • @slightlylate Alex Russell on x
    If only they hadn't blown the whole budget on WebKit/Safari. https://twitter.com/...
  • @seldo Laurie Voss on x
    I mean it's obviously not cool that Apple ignored a security researcher but “an app installed from the App store can access your personal information” does not seem like a smash-the-glass emergency to me. https://twitter.com/...
  • @theevilbit Csaba Fitzl on x
    The most interesting thing about these 0days that I also reported the Core Duet privacy info leaks, but for macOS, long time ago. That was fixed. Apparently iOS was also vulnerable and Apple didn't realize it. Maybe I should start looking into iOS. 👀 https://habr.com/...
  • @lrvick Lance R. Vick on x
    I found a DRM bypass in MacOS recently. Rather than cash it in with Apple, I gave it to a group actively working to undermine their walled gardens. Apple doesn't care about security, privacy, or freedom, so I don't care about them.
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    We just updated the story with comments from the researcher who found the bugs. https://www.vice.com/... https://twitter.com/...
  • @slightlylate Alex Russell on x
    Every OS has security issues. What's important to understand here is how the approaches differ. Other OSes let you move your computing to a safer layer (the web) and deliver choice + competition about those protections. Only iOS keeps mobile down in the (security) dirt. https://t…
  • @alanlangford_ca @alanlangford_ca on x
    I presume fixing these exploits will make it harder for Apple to spy on its employees... cc @ashleygjovik https://twitter.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: A researcher has published the source code for exploits that take advantage of three unpatched iPhone bugs. Another researcher said he was able to reproduce exploits in 30 mins. But bugs are not *that* dangerous for users. https://www.vice.com/...
  • @alex @alex on x
    not fun to watch iOS start to feel more like Windows XP before SP1 https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    It looks like Apple has a bug bounty problem. This researcher claims they've reported 4 zero days, 3 of which are still exploitable in iOS 15. This after a Spanish researcher dumped a lockscreen bypass because he says Apple ignored him. https://therecord.media/... https://twitter…
  • @campuscodi Catalin Cimpanu on x
    Nothing major like an RCE, hence the reason why Apple hasn't prioritized them (per someone familiar with Apple's bbp inner workings) https://twitter.com/...
  • @marcoarment Marco Arment on x
    Click through to see the Game Center exploit in particular. It's rough. Things like this should almost never slip through the cracks with a functioning security program. Instead, with Apple, it's commonplace. That's so deeply broken, yet nothing changes. What will it take?
  • @marcoarment Marco Arment on x
    Security relations are developer relations. What will it take for Apple to change their entire CULTURE of how they treat outside developers? https://twitter.com/...
  • @msuiche @msuiche on x
    Rumors are saying that Apple can't afford to pay the maximum payouts on bug bounties and that's why they never did. I'm starting a fund raising to help Apple, reach out if you want to donate and assist Apple through that difficult period.
  • @swiftonsecurity SoS on x
    But seriously how Apple doesn't just pay 100k for every bug is the dumbest penny pinching when you've got a trillion fucking dollars https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    Another researcher annoyed with how Apple handled his report, from just a few days ago: https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    Apple will never change their ways until they're publicly shamed. Sad to see it has come to this.
  • @keleftheriou Kosta Eleftheriou on x
    It appears to be able to pull my entire contact list and lots of details about my conversations, with no user prompt of any kind. I see a ton of my own private data in each of these 3 sections: https://twitter.com/...
  • @keleftheriou Kosta Eleftheriou on x
    The website at the top of the thread seems to be having some intermittent issues. Link to archived page: https://archive.is/...
  • @keleftheriou Kosta Eleftheriou on x
    Can confirm the exploit runs successfully on iOS 14.8: https://twitter.com/...
  • @mahemoff @mahemoff on x
    “I've reported four 0-day vulnerabilities this year between March 10 and May 4, as of now three of them are still present in the latest iOS version (15.0) and one was fixed in 14.7, but Apple decided to cover it up and not list it on the security content page” 😮
  • @mahemoff @mahemoff on x
    The report shows any app could access contact details without requesting permission. That's what Apple just decided to sweep under the rug. https://habr.com/... via https://news.ycombinator.com/ ...
  • @renakunisaki @renakunisaki on x
    https://habr.com/... 3 iOS 0days dropped. Also, what the fuck is Apple doing with this info!? Why do they need to log your menstrual cycles? https://twitter.com/...
  • @satefan Stefan Arentz on x
    Why is Apple not working with security researchers who are finding highly critical bugs like these? They should put someone competent in charge to run a proper security bounty program. It is just so bizarre that this is completely mismanaged. https://habr.com/...