TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

About the security content of iOS 12.4.9

160 pointsby axyjoover 4 years ago

10 comments

alewi481over 4 years ago
I'd like to give kudos to Apple for including the iPhone 5S in this security update, which was released on September 20, 2013, over 7 years ago! Supporting a product for even 3 years is rare in the smartphone world.
评论 #25001818 未加载
评论 #25001520 未加载
评论 #25001554 未加载
评论 #25001490 未加载
评论 #25004420 未加载
评论 #25001868 未加载
评论 #25008893 未加载
tptacekover 4 years ago
A tricky thing about flagging &quot;in the wild exploited vulnerabilities&quot; in a title like this is that it suggests that sev:crit vulnerabilities in other updates that aren&#x27;t flagged like this aren&#x27;t being exploited in the wild. We get confirmation of only a subset of exploited vulnerabilities.<p>We&#x27;d be better off with a more neutral title, like &quot;fixing severe vulnerabilities&quot; or something like that.
评论 #25001352 未加载
评论 #25001485 未加载
评论 #25003021 未加载
评论 #25005934 未加载
patio11over 4 years ago
Note that there are similar issues in macOS, too. <a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT211947" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT211947</a> &lt;-- Catalina 10.15.7 Supplemental Update notes
评论 #25004265 未加载
heavyset_goover 4 years ago
I think it&#x27;s interesting how iOS exploits are cheaper[1] than Android exploits, because iOS exploits are so plentiful in comparison to Android exploits.<p>[1] <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2019&#x2F;09&#x2F;for-the-first-time-ever-android-0days-cost-more-than-ios-exploits&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2019&#x2F;09&#x2F;for-t...</a>
评论 #25001558 未加载
评论 #25003970 未加载
评论 #25001548 未加载
评论 #25003339 未加载
评论 #25001877 未加载
评论 #25001651 未加载
saagarjhaover 4 years ago
I think this is the first time Apple has mentioned that the bugs they fixed were exploited in the wild? A welcome change if so.
jamiehallover 4 years ago
Linking to the 14.2 list (<a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT211929" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;HT211929</a>) might be better? After clicking the headline link, it took me a few seconds to understand why we were caring about updates for the iPhone 5 and 6...
评论 #25001590 未加载
sebastien_bover 4 years ago
The problem with these updates is that it&#x27;s only for devices that can only support up to iOS 12 (in this case) - if you have another device that supports anything higher but don&#x27;t want upgrade to the latest iOS, you still won&#x27;t get these iOS 12 security updates - they force you to upgrade the entire OS to get them.
评论 #25005941 未加载
hosteurover 4 years ago
Can these vulns be used to jailbreak a phone?
MrStonedOneover 4 years ago
Anybody get a bitter sweet feeling when ever these reported and fixed security exploits announcements happen?<p>It&#x27;s good that users aren&#x27;t going to risk getting hacked by such vulnerabilities, but its bad that users can no longer uses these exploits to gain administrative control over their property.
评论 #25004012 未加载
评论 #25001729 未加载
评论 #25002232 未加载
评论 #25006030 未加载
swileyover 4 years ago
Maybe I got hit with one of these, my phone stopped being able to answer phone calls and auto focus stopped working (like something re flashed the firmware on a bunch of the internal peripherals.)<p>I was going to wait until the software on my pinephone was more mature but that pushed me over the edge to get power management working on my own and make sure it could make phone calls. I think dumping iOS has done a lot for my mental health and I&#x27;m glad to have left it.
评论 #25001409 未加载
评论 #25001591 未加载