back
230 comments
Always a smile when I see my blog posted on hn:)

To answer three questions:

1) this was not reported in the context of any bug bounty[0], and the total conversation between me and Apple is 4 emails (1: hello do you plan to fix this? 2: can you reproduce this on the newest ios17? 3: no. 4: if you are able to reproduce it on ios17 let us know)

2) exfiltration is obviously possible, I’m not sure why I would even need to specify that any page is able to read its own contents using JavaScript

3) the iPhone 6s and 15.8 are still seemingly supported by Apple.

[0] and you won’t find me on any bug bounty websites except for where I try to get contact with humans, see https://joshua.hu/slack-is-broken-with-noscript

You didn’t answer the biggest question: being able to read /etc/passwd does not imply being able to read any of the sensitive files listed under “What files could somebody steal? Well, there’s always:”. Did you actually test any of those?
Getting in touch with an human is generally "easy": getting in touch with an engineer isn't.

It's sad that one has to open a bug bounty request to get an engineer to look into an issue like the one you described in your linked blog post.

It,'s always a fun and interesting read when your posts hit HN.

How much time would you estimate goes into researching? And do you have any pointers for someone which want to dip their toes into this vast sea of exploration?

> exfiltration is obviously possible, I’m not sure why I would even need to specify that any page is able to read its own contents using JavaScript

Things that are obvious to you may be non-obvious to other people, including the readers of your blog.

Welcome to HN, in as gentle a way possible I refute this statement

> Apple continues to support nearly-decade-old devices like the iPhone 6S, which and iOS 15.8 is still powering those devices, seemingly with official Apple support, with the latest update from October the 25th, which addressed some security vulnerabilities.

With: try to update your Apple Watch with a device running the latest iOS 16

I feel this is misleading as most iPhone users are totally aware that iPhone Models not running iOS 17 are not being actively updated.

The list is widely published: https://support.apple.com/guide/iphone/models-compatible-wit...

Any model more than 5 years old (Xr and Xs) are essentially not being updated and not secure. So an iPhone 1, 3, 5, 6, 7, 8 and X are all not secure and most people who use the iPhone are totally aware of this.

It's like writing an article that Windows 7 is insecure and Microsoft isn't patching it. This is essentially their policy in most cases.

This is about the browser, not the OS. The unique thing about apple is that they tie the browser to the OS. So you won't even get application updates, which is quite surprising for anyone that has ever touched a computer.

That is some Windows 98 nonsense right there.

I have been a developer and nerd since 25 years, and I always expected that Apple also patches some previous versions. E.g. around a week ago they released both iOS 17.2.1 and iOS 16.7.4: https://support.apple.com/en-us/HT201222

So why should I assume that latest iOS 16 isn't completely patched? I think it's a shame to say at least that Apple has no public policy of how which OS versions are supported and which are not, it's just guesswork. Whereas I definitely know how long Microsoft supports Windows versions, e.g. Windows 10 until October 14th, 2025: https://learn.microsoft.com/en-us/lifecycle/products/windows...

I’m pretty sure most iPhone users are unaware of which version of iOS they run.
This is addressed in the second paragraph of the article. The iPhone 6S had an OS update in October 2023 (iOS 15.8) which included a security fix for a different issue. The Chromium security issue was fixed in June 2023.
According to the link Xs is supported.
/etc/passwd is the same on every device because it is in the system image, which is world readable. I don't think this exploit can be used to read the call history database as the author implies because it is outside of the sandbox profile.
It probably does let you grab cookies and browsing history from Chrome, though.
Yeah the author goes a bit far in their hypotheticals, straight into fantasy.

Also not sure I agree with the implication that Apple shouldn’t publish which vulnerabilities they’ve patched (the only logical conclusion because the alternative, patching every version in perpetuity, is unrealistic).

Apple, in my opinion, does a very good job of supporting old devices. Buying an iPhone and keeping it for 6 years is a great strategy and when amortising the cost of the phone over those 6 years, it's price competitive with Android.

I do wish legislators forced Apple and Google to give users a path to install an alternative OS on their device. That would enable old iPhones(and Androids) to have their lifetime extended further.

> I do wish legislators forced Apple and Google to give users a path to install an alternative OS on their device.

All Google phones allow installation of alternative OSes (and are pretty much the only phones that allow resigning the boot loader so they're still secure - which is why they're chosen by projects like GrapheneOS). Why do you think they need to be forced into anything? You can buy a Pixel right now and run an alternative OS.

>Buying an iPhone and keeping it for 6 years is a great strategy and when amortising the cost of the phone over those 6 years, it's price competitive with Android.

What's stopping you from keeping your Android 6 years making it an event better value? Most people I know don't throw away their Androids after 3 years but keep them as long as iPhones. Basically until it breaks/dies. So far I don't know anyone who got hacked and suffered damages for using an Android that stopped getting updates.

Yes, Apple is supporting older devices, but has made my SE 2020 nearly unusable (slow as hell, horrible UI bugs when typing) after updating to iOS 17. Everything worked perfectly until then. It seems as though Apple wants me to buy a more expensive phone. A friend had the exact same problem and now upgraded to a newer model.
No real change is going to happen. Out of all the mobile phone users out there, likely no more than 0.1% will ever consider installing alternative OS on their phone, even if allowed by law. Just look at the size of the custom ROM community in Android and real world impact.
> After contacting Apple […]

I’d be very curious to see HOW they contacted Apple. Depending on if you’re reaching out to security or just filing a standard radar I’d expect a very different answer.

Also, was it reported to the WebKit team? If that is where the bug is, perhaps that’s who should be taking the report?

It can make a big difference who reads the ticket. I might see something come in and think oh yeah that'll take me 5 min to fix and I'll just do it, but if someone else unknowledgeable about the feature sees it, or a PM... it might get closed as won't fix at best or just rot for 10 years.
OP here. It was reported to product-security@apple.com.
This is a 10 year old phone, released in 2014. Edit. I was wrong, 2015, sorry
This bug touches nothing hardware specific. In alternative timeline where mobile OSes arent fisher price parodies of proper operating systems, they could push the same image to all iphones and have a proper hardware abstraction layer take care of the specific details.

There is nothing fundamentally incompatible about the last couple of generation of iphones. ARMv8 CPU, PowerVR derived GPU. If the mobile computing space weren't driven by greed, this would be a non issue.

A Sandy Bridge era intel machine deployed in 2011 is easily capable of running the latest Linux, BSD or win10. And in the case of the first two, I'd wager it will continue to be viable for the foreseeable future.

Apple still sells previous phones as lesser, but still not very affordable, models. The iPhone 7 was released in September 2016 and discontinued in September 2019. It is also on iOS 15.8 so presumably also vulnerable to this. That would be about 4 years of security updates. Not the worst but not beating what e.g. Google promises for Pixel phones now.
It's fine for a vendor to completely abandon 10 year old hardware but if you can still pay 30% App Store tax/pay for iCloud/etc, the security fixes should be backported as well. The current situation is charging full price for inferior (or maybe even dangerous) product: Apple wants to have its cake and eat it too.
It’s an issue of expectations. If Apple advertises security support then it’s fraudulent to not deliver it; on the other hand, if they advertise an EOL date, then I’d agree there’s no reasonable expectation of security updates. But what they actually do is neither, they communicate very little, supporting some past iOS versions fully and others to degrees that only they know, resulting in them profiting off a reputation for backporting security updates while not actually binding themselves to deliver it, or, often, doing so.

Like the battery issue, I feel the whole issue is communication. Apple needs to communicate when they EOL OS versions. You don’t otherwise know it, partly because EOL OS’s, including this phone’s, still get security updates, just not all of them.

Does apple release jailbreak tools for ten year old phones?
Correct. The issue is it is not commonly known that Apple isn't actually backporting fixes for exploits while it has been claiming to update the phones: this is earth-shaking[^1] news

[^1] It would be completely reasonable to say "Earth-shaking? Really? You expect security backports for a decade?" I've been in mobile my whole career, iOS for 7 years, starting from jailbreaking the original iPhone, then worked on Android itself for 7 years. I am sure significant decisions were made assuming this was the case.

My 10 year old laptop is still getting OS updates
Some iOS 15 phones like the 5S/SE have no newer comparable phones which makes upgrading difficult. Oh dear, I suppose not browsing the web is another option.
It's worrying to me since it's often kids who get the hand-me-down phones. I don't think they are going to know how vulnerable their data is. Surely Apple could at least let a community compile latest security updates, if they don't wanna invest their many riches in it? People often can't afford newer phones, and their data is vulnerable.
How do we know they won’t patch it in like an iOS 15.8.1 update?

Even iOS 12 had a security update in 2023 still.

Would be great to get Linux running on and driver coverage for all of the system-on-chip of these devices. Talent exists for this but they are busy with their jobs or more interesting problems.
Moving the photos and videos to a hard rive is a pain usb is buggy, icloud is useless. Cheaper iphones have very little storage and there is no ssd slot either. It means, when the phone is full you have to buy a new one. If you want to update (assuming updates are available) you have to do hours of manual photo and video deletion to make space for the update.

If they really wanted to update phones that are full they could move the images/video to their server until the update is done.

I think a lot of people here are missing an important point here that Apple has always been fairly ambiguous about what their level of support is for older devices beyond major feature updates.

If it weren't for a friend giving me his old iPhone XS as thanks for a favor, I'd probably still be using my old iPhone 6s--and I would not have worried about it from a security perspective purely because (as the article notes) Apple is still releasing security fixes for iOS 15. I'd feel differently if Apple had publicly stated that all iOS 15 security fixes from now on will be on a minimum effort basis only.

Those Apple commercials purporting their ecosystem was the safest/secure have aged like old milk
I don't know what OP expects from such an old device. Apple goes above and beyond other manufacturers in terms of support.

The phone is almost 10 years old, the only thing Apple should do is send out a push notification warning users their device is no longer supported.

Microsoft still release security updates sometimes for 22 years old Windows XP.
>Apple declined to comment for this article.
This is true for pretty much every vendor. Security fixes do not all get backported to every previous version of something. Newer iPhone do not just run the latest version of iOS, but they are more secure from a hardware perspective too.
fwiw I tested this and the exploit doesn't work on iOS 16 which is the latest available for a 2017 iPhone X.
The iPhone 8 was sold new less than 3 years ago. Okay, new features shouldn't be expected, but patching known vulnerabilities should be required.
The iPhone 6S mentioned was released in 2015, but should run iOS 15, which Apple still should be releasing security updates for?
When opening the page, your /etc/passwd is there for the world to see.

...more precisely, for you to see; this needs to be combined with something to send back data (JS?) to be truly exploited.

That is why I am an android dude, you will always find a random ROM on xda with the latest android security patch and sometimes even the latest android version on devices 10+ years old even if the manufacturer has stopped supporting it a while ago.