Apple Issues Emergency Security Updates to Close a Spyware Flaw
nytimes.com
nytimes.com
It's September. The NYTimes says: "Apple’s security team has been working around the clock to develop a fix since Tuesday, after researchers at Citizen Lab, a cybersecurity watchdog organization at the University of Toronto, discovered that a Saudi activist’s iPhone had been infected with spyware from NSO Group."
So has Apple been sitting on this since March, or has CitizenLab?
[1] https://citizenlab.ca/2021/09/forcedentry-nso-group-imessage...
I'd rather the flaw wasn't there in the first place, but a remarkable effort by both parties given that it was there.
> Recent re-analysis of the backup yielded
Further down has the timeline of when Apple was informed and acted.
EDIT: and for completeness link to the mentioned other discussion, which makes this a dupe: https://news.ycombinator.com/item?id=28516095
A normal smaller tech company is expected to create an advanced description of what happened. Apple doesn't give any info at all to regular users, no one i know has heard about this, not even seen a "very important to update" message, just a silent "update 11.6".
In my mind everyone with an Apple device should get a huge warning pop up on their screen with the text "everything on your computer has been potentially compromised - update now to remedy (for now at least)" in all caps.
macOS 11.6: https://support.apple.com/en-us/HT212804