To answer three questions:
1) this was not reported in the context of any bug bounty[0], and the total conversation between me and Apple is 4 emails (1: hello do you plan to fix this? 2: can you reproduce this on the newest ios17? 3: no. 4: if you are able to reproduce it on ios17 let us know)
2) exfiltration is obviously possible, I’m not sure why I would even need to specify that any page is able to read its own contents using JavaScript
3) the iPhone 6s and 15.8 are still seemingly supported by Apple.
[0] and you won’t find me on any bug bounty websites except for where I try to get contact with humans, see https://joshua.hu/slack-is-broken-with-noscript
It's sad that one has to open a bug bounty request to get an engineer to look into an issue like the one you described in your linked blog post.
How much time would you estimate goes into researching? And do you have any pointers for someone which want to dip their toes into this vast sea of exploration?
Things that are obvious to you may be non-obvious to other people, including the readers of your blog.
> Apple continues to support nearly-decade-old devices like the iPhone 6S, which and iOS 15.8 is still powering those devices, seemingly with official Apple support, with the latest update from October the 25th, which addressed some security vulnerabilities.
With: try to update your Apple Watch with a device running the latest iOS 16
The list is widely published: https://support.apple.com/guide/iphone/models-compatible-wit...
Any model more than 5 years old (Xr and Xs) are essentially not being updated and not secure. So an iPhone 1, 3, 5, 6, 7, 8 and X are all not secure and most people who use the iPhone are totally aware of this.
It's like writing an article that Windows 7 is insecure and Microsoft isn't patching it. This is essentially their policy in most cases.
That is some Windows 98 nonsense right there.
So why should I assume that latest iOS 16 isn't completely patched? I think it's a shame to say at least that Apple has no public policy of how which OS versions are supported and which are not, it's just guesswork. Whereas I definitely know how long Microsoft supports Windows versions, e.g. Windows 10 until October 14th, 2025: https://learn.microsoft.com/en-us/lifecycle/products/windows...
Also not sure I agree with the implication that Apple shouldn’t publish which vulnerabilities they’ve patched (the only logical conclusion because the alternative, patching every version in perpetuity, is unrealistic).
I do wish legislators forced Apple and Google to give users a path to install an alternative OS on their device. That would enable old iPhones(and Androids) to have their lifetime extended further.
All Google phones allow installation of alternative OSes (and are pretty much the only phones that allow resigning the boot loader so they're still secure - which is why they're chosen by projects like GrapheneOS). Why do you think they need to be forced into anything? You can buy a Pixel right now and run an alternative OS.
What's stopping you from keeping your Android 6 years making it an event better value? Most people I know don't throw away their Androids after 3 years but keep them as long as iPhones. Basically until it breaks/dies. So far I don't know anyone who got hacked and suffered damages for using an Android that stopped getting updates.
I’d be very curious to see HOW they contacted Apple. Depending on if you’re reaching out to security or just filing a standard radar I’d expect a very different answer.
Also, was it reported to the WebKit team? If that is where the bug is, perhaps that’s who should be taking the report?
There is nothing fundamentally incompatible about the last couple of generation of iphones. ARMv8 CPU, PowerVR derived GPU. If the mobile computing space weren't driven by greed, this would be a non issue.
A Sandy Bridge era intel machine deployed in 2011 is easily capable of running the latest Linux, BSD or win10. And in the case of the first two, I'd wager it will continue to be viable for the foreseeable future.
Like the battery issue, I feel the whole issue is communication. Apple needs to communicate when they EOL OS versions. You don’t otherwise know it, partly because EOL OS’s, including this phone’s, still get security updates, just not all of them.
[^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Android itself for 7 years. I am sure significant decisions were made assuming this was the case.
Even iOS 12 had a security update in 2023 still.
If they really wanted to update phones that are full they could move the images/video to their server until the update is done.
If it weren't for a friend giving me his old iPhone XS as thanks for a favor, I'd probably still be using my old iPhone 6s--and I would not have worried about it from a security perspective purely because (as the article notes) Apple is still releasing security fixes for iOS 15. I'd feel differently if Apple had publicly stated that all iOS 15 security fixes from now on will be on a minimum effort basis only.
The phone is almost 10 years old, the only thing Apple should do is send out a push notification warning users their device is no longer supported.
...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.