Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
And for even more security...

View attachment 1830564
And then do this:
1631565964667.png


🤣 😛
 
Nothing yet on The Verge about either the patch, or the security hole it fixes

they seem to have devolved into a what maximises clicks publication
and they know negative Appe stories work the best
 
  • Like
Reactions: BulkSlash
And now the BIG question.

Does the patch only prevent it from happening, or does it block what is already on the phone?

Or do we now need to figure out how to remove it?
I’d argue we have to assume the software has been installed on every single iOS and Mac device in existence today. Removal Of such software could only be done by Apple. If they decide to not publish that, we may never know. The least this patch can do is blocking the exploit.
 
Question, how urgent do I need to download this update? From my understanding, a PDF download is what triggers this exploit? So if I have not downloaded and opened a PDF file from a dodgy website, I should be fine, is that how it works?

Im just confused because I have only been using my phone to visit social media, firefox, and a few trusted apps, and nothing else.
 
Reminds me of apple unwilling to outcompete government or institutions payments to security researchers choosing To notify apple security bugs before selling them off.

If apple needs public exposure To fix every single security bug, the iOS in and out of itself, will no longer be able to secure our data, jailbroken or not, especially since user cannot remedy those security issues themselves without turning off the device.
 
Question, how urgent do I need to download this update? From my understanding, a PDF download is what triggers this exploit? So if I have not downloaded and opened a PDF file from a dodgy website, I should be fine, is that how it works?

Im just confused because I have only been using my phone to visit social media, firefox, and a few trusted apps, and nothing else.
That exploit might be triggered whether you download PDF or not. I’m not transferring PDF through iMessage either, but Apple can choose to not fully disclose the exploits capability, leaving us somewhat in the dark, probably for the safety of general public as well.
 
Question, how urgent do I need to download this update? From my understanding, a PDF download is what triggers this exploit? So if I have not downloaded and opened a PDF file from a dodgy website, I should be fine, is that how it works?

Im just confused because I have only been using my phone to visit social media, firefox, and a few trusted apps, and nothing else.
See FORCEDENTRYNSO Group iMessage Zero-Click Exploit Captured in the Wild - CitizenLab

Devices affected by CVE-2021-30860 per Apple:
All iPhones with iOS versions prior to 14.8, All Mac computers with operating system versions prior to OSX Big Sur 11.6, Security Update 2021-005 Catalina, and all Apple Watches prior to watchOS 7.6.2.
 
Why Apple, Google, and Microsoft don't sue such companies and run their resources to the ground?

What would be your cause of action here?

Sue in which country and for what reason?

I think there are in progress lawsuits over past hacks. Country? US (NSO has US offices I think) or Israel.
Cause? Selling exploits that are then used for "evil" purposes, violating laws on hacking user data, etc.

Here's one from 2019 over a Whatsapp exploit:
 
Why Apple, Google, and Microsoft don't sue such companies and run their resources to the ground?
Google, Microsoft and some other tech companies have joined Facebook's pending lawsuit over NSO's Whatsapp breach. Why Apple isn't joining in I don't know. They'd certainly have standing after the recent news ...

 
With the number of exploits coming in through iMessage vulnerabilities, it is reminiscent of Flash. Apple may need to refactor the iMessage code base with security in mind from the ground up. I am not sure specifically what Apple is doing from a development side on iOS 15, but it needs work.
 
  • Like
Reactions: BulkSlash
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.