About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.
About less people being able to afford it - this again depends on what ZERODIUM intends to do with it. They may sell it for cheap and count on a large number of sales because, again, iOS is so popular.
> Apple iOS, like all operating system, is often affected by critical security vulnerabilities, however due to the increasing number of security improvements and the effectiveness of exploit mitigations in place, Apple's iOS is currently the most secure mobile OS. But don't be fooled, secure does not mean unbreakable, it just means that iOS has currently the highest cost and complexity of vulnerability exploitation and here's where the Million Dollar iOS 9 Bug Bounty comes into play.
BTW, I guess Flash is as popular as iOS9 (the Steam hardware survey used to show that 99.9% of the Steam users had Flash installed), yet, as stirlo says, they only paid up to $30k for Flash exploits.
You do make a great point with that Flash comparison, though.
"Mobile: VUPEN offered several different remote code execution and local privilege escalation exploits for Android; however, not all of them were 0day and Hacking Team deemed that the prices were too high to purchase. Though there was interest in purchasing exploits for iOS, VUPEN said they were limited to certain customers, presumably high-paying government agencies." [1]
"iOS exploit pricing: Adriel stated he was supply-constrained for iOS RCE exploits because exploit developers frequently had their own connections to sell them, and that he believed that such exploits were overpriced. An exclusive exploit sale could cost over a million dollars, [...]." [1]
With regards to users flash player has more users than iOS but the exploit was cheaper, while these users might not be as valuable as iOS users neither market is what you would consider small.
And finally it's unlikely they would sell it to mass users for extremely cheap and risk it leaking. It's probably more out of desperation, Vupen has heaps of long term customers who they have promised the ability to hack phones to, it's probably embarrassing to them if they can't hack them most popular phone model out there.