Security News > 2021 > September > Exploit code released for three iOS 0-days that Apple failed to patch
Proof-of-concept exploit code for three iOS zero-day vulnerabilities was published on GitHub after Apple delayed patching and failed to credit the researcher.
The researcher who found the four zero-days reported them to Apple between March 10 and May 4.
"Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day.
Apple did not reply to BleepingComputer's email to validate any of the researcher's claims.
Software engineer Kosta Eleftheriou confirmed that the app designed to exploit Gamed zero-day and harvest sensitive user information works on iOS 15.0, the latest iOS version.
"All this information is being collected by Apple for unknown purposes, which is quite disturbing, especially the fact that medical information is being collected," the researcher said, referring to the analyticsd zero-day silently patched in iOS 14.7.
News URL
Related news
- Exploit available for new critical TeamCity auth bypass bug, patch now (source)
- Apple fixes two new iOS zero-days exploited in attacks on iPhones (source)
- Apple fixes two actively exploited iOS zero-days (CVE-2024-23225, CVE-2024-23296) (source)
- Exploit released for Fortinet RCE bug used in attacks, patch now (source)
- GoFetch security exploit can't be disabled on M1 and M2 Apple chips (source)
- Exploit released for Palo Alto PAN-OS bug used in attacks, patch now (source)
- Maximum severity Flowmon bug has a public exploit, patch now (source)