https://www.bleepingcomputer.com/news/apple/apple-silently-fixes-ios-zero-day-asks-bug-reporter-to-keep-quiet/ BleepingComputer.com logo * * * [ ] [Login] [Sign up] * * * [ ] [Login] [Sign up] * News + Featured + Latest + Russia and China left out of global anti-ransomware meetings Russia and China left out of global anti-ransomware meetings + Verizon digital carrier Visible customer accounts were hacked Verizon digital carrier Visible customer accounts were hacked + OpenSea NFT platform bugs let hackers steal crypto wallets OpenSea NFT platform bugs let hackers steal crypto wallets + Apple silently fixes iOS zero-day, asks bug reporter to keep quiet Apple silently fixes iOS zero-day, asks bug reporter to keep quiet + MyKings botnet still active and making massive amounts of money MyKings botnet still active and making massive amounts of money + Apple silently fixes iOS zero-day, asks bug reporter to keep quiet Apple silently fixes iOS zero-day, asks bug reporter to keep quiet + Australia to tackle ransomware data breaches by deleting stolen files Australia to tackle ransomware data breaches by deleting stolen files + EU legislation introduced to ban anonymous domain registration EU legislation introduced to ban anonymous domain registration * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Virus Removal Guides + Latest + Most Viewed + Ransomware + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove the Smashapps.net Search Redirect Remove the Smashapps.net Search Redirect + Remove the Smashappsearch.com Search Redirect Remove the Smashappsearch.com Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to make the Start menu full screen in Windows 10 How to make the Start menu full screen in Windows 10 + How to install the Microsoft Visual C++ 2015 Runtime How to install the Microsoft Visual C++ 2015 Runtime + How to open an elevated PowerShell Admin prompt in Windows 10 How to open an elevated PowerShell Admin prompt in Windows 10 + How to Translate a Web Page in Google Chrome How to Translate a Web Page in Google Chrome + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + File Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Apple * Apple silently fixes iOS zero-day, asks bug reporter to keep quiet * * Apple silently fixes iOS zero-day, asks bug reporter to keep quiet By Sergiu Gatlan * October 13, 2021 * 11:25 AM * 1 Apple silently fixes iOS zero-day, asks bug reporter to keep quiet Apple has silently fixed a 'gamed' zero-day vulnerability with the release of iOS 15.0.2, on Monday, a security flaw that could let attackers gain access to sensitive user information. The company addressed the bug without acknowledging or crediting software developer Denis Tokarev for the discovery even though he reported the flaw seven months before iOS 15.0.2 was released. Failures to credit bug reports In July, Apple also silently patched an 'analyticsd' zero-day flaw with the release of 14.7 without crediting Tokarev in the security advisory, instead promising to acknowledge his report in security advisories for an upcoming update. Since then, Apple published multiple security advisories (iOS 14.7.1, iOS 14.8, iOS 15.0, and iOS 15.0.1) addressing iOS vulnerabilities but, each time, they failed to credit his analyticsd bug report. "Due to a processing issue, your credit will be included on the security advisories in an upcoming update. We apologize for the inconvenience," Apple told him when asked why the list of fixed iOS security bugs didn't include his zero-day. Two days ago, after iOS 15.0.2 was released, Tokarev emailed again about the lack of credit for the gamed and analyticsd flaws in the security advisories. Apple replied, asking him to treat the contents of their email exchange as confidential. This wouldn't be the first time Apple's security team asked for confidentiality: the first time happened in August when he was told the gamed zero-day would be fixed in a future security update and urged not to disclose the bug publicly. "All things considered, they treat gamed vulnerability a bit better that analyticsd, at least they don't ignore me and lie to me this time," Tokarev told BleepingComputer. Seems that they don't have a separate protocol on handling reports which were already disclosed. And if this message contains a legit excuse, they could save a tiny bit of reputation by making it public. But it's up to them, I won't disclose full message until I get credit. 2/3 pic.twitter.com/iG6waUELtk -- Denis Tokarev (@illusionofcha0s) October 13, 2021 Other bug bounty hunters and security researchers have also reported having similar experiences when reporting vulnerabilities to Apple's product security team via the Apple Security Bounty Program. Some said bugs reported to Apple were silently fixed, with the company failing to give them credit, just as it happened in this case. Others weren't paid the amount listed on Apple's official bounty page [1, 2] or haven't received any payment at all, while some have been kept in the dark for months on end with no replies to their emails. Two zero-days left to (silently) patch In total, Tokarev found four iOS zero-days and reported them to Apple between March 10 and May 4. In September, he published proof-of-concept exploit code and details on all iOS vulnerabilities after the company failed to credit him after patching the gamed zero-day in July. If attackers would successfully exploit the four vulnerabilities on unpatched iOS devices (i.e., iPhones and iPads), they could gain access and harvest Apple ID emails, full names, Apple ID authentication tokens, installed apps info, WiFi info, and analytics logs (including medical and device information). The complete list of iOS zero-days reported by Tokarev includes: * Gamed 0-day (fixed in iOS 15.0.2): Bug exploitable through user-installed apps from App Store and giving unauthorized access to sensitive data normally protected by a TCC prompt or the platform sandbox ($100,000 on the Apple Security Bounty Program page) * Nehelper Enumerate Installed Apps 0-day (iOS 15.0): Allows any user-installed app to determine whether any app is installed on the device given its bundle ID. * Nehelper Wifi Info 0-day (iOS 15.0): Makes it possible for any qualifying app (e.g., possessing location access authorization) to gain access to Wifi information without the required entitlement. * Analyticsd (fixed in iOS 14.7): Allows any user-installed app to access analytics logs. "We saw your blog post regarding this issue and your other reports. We apologize for the delay in responding to you," Apple told Tokarev 24 hours after publishing the zero-days and the exploit code on his blog. "We want to let you know that we are still investigating these issues and how we can address them to protect customers. Thank you again for taking the time to report these issues to us, we appreciate your assistance." Apple has also fixed a second zero-day vulnerability in iOS 15.0.2 and iPadOS 15.0.2, actively exploited in the wild to target iPhones and iPads. This bug, tracked as CVE-2021-30883, is a critical memory corruption flaw in the IOMobileFrameBuffer, allowing malicious applications to execute commands on vulnerable devices with kernel privileges. Apple has not replied to emails BleepingComputer sent since September 24, asking for an official statement and more details. Related Articles: Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks Researcher drops three iOS zero-days that Apple refused to fix Apple patches new zero-day bug used to hack iPhones and Macs Apple fixes iOS zero-day used to deploy NSO iPhone spyware Apple fixes bug that breaks iPhone WiFi when joining rogue hotspots * Apple * iOS * Zero-Day * * * * * Sergiu Gatlan Sergiu Gatlan is a reporter who covered cybersecurity, technology, Apple, Google, and a few other topics at Softpedia for more than a decade. Email or Twitter DMs for tips. * Previous Article * Next Article Comments * Wh1t3Ryn0 Photo Wh1t3Ryn0 - 7 hours ago + + Apple, like Google and others are beyond shady when it comes to bug bounty recognition and payment. Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] [Bleeping_Computer_CFM_V2_2021] Popular Stories * Android Study reveals Android phones constantly snoop on their users * Apple Emergency Apple iOS 15.0.2 update fixes zero-day used in attacks Newsletter Sign Up To receive periodic updates and news from BleepingComputer, please use the form below. [ ] [Submit] Newsletter Sign Up [ ] [Submit] * Follow us: * * * * Main Sections * News * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * File Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement Copyright @ 2003 - 2021 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT