Don't miss the latest stories
Advertise Newsletter
Network
  • The Creative Finder
  • The Bazaar
  • Deals
  • Status Is Down
Community
  • Sign up / Log in
  • Discussion Forums
  • Calendar of Events
NEW

Follow

Share this

Cybersecurity
Apple
iOS
macOS
Smartphones
  • macOS
  • Smartphones
MENU
  • Advertise with us
  • Submit tip/feedback
  • Work with us
  • Subscribe to newsletter
  • Subscribe to RSS
Advertise here
Advertisement

Apple Accused Of Ignoring Vulnerabilities That Let Any App Access Your Messages

By Ell Ko, 28 Sep 2021

Subscribe to newsletter
Like us on Facebook

Image via ID 216231196 © Wachiwit | Dreamstime.com

In a bid to enhance the security of its ecosystem, Apple introduced the Security Bounty Program to the public in 2019.

This scheme was aimed to encourage researchers to report any critical vulnerabilities with, or techniques used to exploit, Apple’s operating systems (OS). As an incentive, payouts of up to a million dollars were offered depending on the tier of discovery, hence the “bounty.”

While this sounds like a highly effective way to encourage users to keep using the OS while attempting to discover vulnerabilities, such as the Pegasus spyware, various reports have surfaced over the last few years that indicate that Apple isn’t doing exactly what it said it would.

In a blog post, one security researcher who prefers to remain anonymous shared their “frustrating experience” with the tech giant.

They stated that they had made four reports between March and May of this year regarding zero-day vulnerabilities, which are critical to users’ privacy.

Despite expecting the vulnerabilities to be patched up quickly, they stated that three of these are still present in the newest iOS 15, and although one was fixed, they were not credited by Apple for discovering it.

“When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time,” the researcher wrote.

Finally, they gave Apple an ultimatum: respond, or they’d release the research to the public. This was apparently ignored, so they went ahead to publish their findings.

Advertisement
Advertisement


One of these is a big hole in Game Center, which reportedly allows any app installed via the App Store to access user data including the Apple ID email used, the full name associated with the Apple ID, and an authentication token.

There is also an alarming opportunity for the app to be granted “complete file system read access” to the Core Duet database. This contains contacts from communications apps such as Mail, iMessage, and even third-party messaging apps.

Not only that, the user’s interactions with these contacts, such as timestamps and even some attachments, are accessible.

It’s clear to see why this needs to be fixed, yet the vulnerability apparently still lingers in iOS 15.

In the blog post, other risks are reported in detail. There are also links to various other accounts of researchers who have faced similar problems with the Security Bounty Program, such as this.

A day after the post was initially published, Apple finally responded to the researcher, acknowledging the blog post and the reports.

“We want to let you know that we are still investigating these issues and how we can address them to protect customers,” the company wrote. “Thank you again for taking the time to report these issues to us, we appreciate your assistance.”

Click through to see the Game Center exploit in particular. It’s rough.

Things like this should almost never slip through the cracks with a functioning security program.

Instead, with Apple, it’s commonplace.

That’s so deeply broken, yet nothing changes.

What will it take?

— Marco Arment (@marcoarment) September 24, 2021




[via MacRumors, image via ID 216231196 © Wachiwit | Dreamstime.com]
Receive interesting stories like this one in your inbox
Advertise here

More related news

Advertise here
Also check out these recent news
Web Design
Link to news page

When Your Website Goes Down, This Is the Page Customers Meet Instead

2027
Link to news page

2027 Already Has A Color Of The Year And It’s Beginning On ‘Grounded’ Territory

IKEA
Link to news page

IKEA & Xbox Press Play On Furniture & Storage Inspired By The Iconic Controller

Fashion
Link to news page

Vogue Presents ‘United Flags of Fashion’ With Top Designers For All 50 States

Coca-Cola
Link to news page

Coca-Cola Pours Fresh Life Into Its Iconic Branding With Worldwide Redesign