• Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
What's Hot

Want Your Mac to Last for Years? Start with These 10 Habits

November 14, 2025

Ordo Sonic Lite review: This electric toothbrush is the perfect stocking filler

November 14, 2025

Samsung Galaxy Tab S11 Ultra review: The ultimate Android tablet

November 13, 2025
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
  • Fintech
  • Startup
  • Games
  • Ar & Vr
  • Reviews
  • How To
  • More
    • Mobile Tech
    • Pc & Laptop
    • Security
Behind The ScreenBehind The Screen
Home»Mobile Tech»Apple patches zero-day flaw in iOS 15, but without crediting outspoken researcher
Mobile Tech

Apple patches zero-day flaw in iOS 15, but without crediting outspoken researcher

July 4, 2022No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Apple patches zero-day flaw in iOS 15, but without crediting outspoken researcher
Share
Facebook Twitter LinkedIn Pinterest Email

Final month safety researcher Denis Tokarev, aka illusionofchaos, shared his expertise of reporting three zero-day iOS vulnerabilities to Apple with particular criticism round how the corporate is gradual to reply, act, and didn’t give him credit score for one of many three flaws that had been patched. Now it seems Apple has fastened one other zero-day flaw, this one in iOS 15 that Tokarev discovered earlier this 12 months, with out giving him credit score.

In September, Tokarev stated that after ready as much as half a 12 months since reporting a number of the vulnerabilities to Apple, he determined to go public with the knowledge.

Ten days in the past I requested for a proof and warned then that I might make my analysis public if I don’t obtain a proof. My request was ignored so I’m doing what I stated I might. My actions are in accordance with accountable disclosure pointers (Google Challenge Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI – in 120). I’ve waited for much longer, as much as half a 12 months in a single case.

On the finish of September, Tokarev shared that he bought a response from Apple that stated they had been nonetheless engaged on the “points” and apologized for the delay.

In his September weblog publish, Tokarev detailed a gamed zero-day flaw (one in every of three) that may enable any app put in from the App Retailer to achieve entry to private person knowledge comparable to Apple ID electronic mail and full identify, Apple ID auth token, full file system learn entry to the Core Duet database, and extra.

See also  It’s Official! Multiview for Live Sports comes to Apple TV

Now Tokarev says Apple has patched the gamed zero-day he found within the iOS 15.0.2 safety replace with out crediting him (through BleepingComputer).

After the primary zero-day flaw Tokarev found and reported to Apple and he wasn’t credited when it was fastened in iOS 14.7 (July 19), the corporate advised him:

“As a result of a processing situation, your credit score shall be included on the safety advisories in an upcoming replace. We apologize for the inconvenience.”

After the second was patched in iOS 15.0.2 with credit score to “an nameless researcher,” Tokarev stated Apple did reply to him in six hours, however apparently didn’t have a option to repair the issue of correctly citing him. In the meantime, Apple nonetheless hasn’t responded to the analyticsd zero-day he discovered that was patched in iOS 14.7.

Tokarev was requested to maintain the newest emails from Apple confidential and he has adopted that request right now.

Appears that they do not have a separate protocol on dealing with experiences which had been already disclosed. And if this message incorporates a legit excuse, they might save a tiny little bit of repute by making it public. Nevertheless it’s as much as them, I will not disclose full message till I get credit score. 2/3 pic.twitter.com/iG6waUELtk

— Denis Tokarev (@illusionofcha0s) October 13, 2021

Nonetheless, they have not replied to my second electronic mail persevering with to disregard my questions on analyticsd vulnerability which I requested precisely a month in the past. pic.twitter.com/sFUhMzvAAU

— Denis Tokarev (@illusionofcha0s) October 13, 2021

FTC: We use revenue incomes auto affiliate hyperlinks. Extra.

See also  Apple Explains Why It Dropped Plan to Detect CSAM in Photos

Take a look at 9to5Mac on YouTube for extra Apple information:



Source link

Apple crediting flaw iOS outspoken patches researcher ZeroDay
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

11 Hidden iOS 26 Features You Probably Haven’t Discovered Yet

November 12, 2025

iOS 26.1 Quietly Changes How You Stop Your iPhone Alarm

November 5, 2025

Apple iPad Pro (M5) review: The best comes at a cost

October 29, 2025

How to Restore the Classic Preview Experience in iOS 26

October 21, 2025
Add A Comment

Comments are closed.

Editors Picks

Empaxis and EXL forge wealth management pact

December 22, 2022

Hackers can see what you’re doing in VR via Big Brother malware

July 25, 2022

Google Pixel 9 Pro vs Pixel 9 Pro XL: What’s the difference?

August 13, 2024

Necromancer action-RPG Undead Horde 2: Necropolis announced

September 3, 2022

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Want Your Mac to Last for Years? Start with These 10 Habits

Ordo Sonic Lite review: This electric toothbrush is the perfect stocking filler

Samsung Galaxy Tab S11 Ultra review: The ultimate Android tablet

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.fr - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.