Apple patches “clickless” 0-day image processing vulnerability in iOS, macOS
arstechnica.com
arstechnica.com
Is it any wonder that a company which has continuously failed for decades to certify resistance against moderate threats keeps getting their security completely invalidated by moderate threats? It should not be; they positively certify for sure that they are useless against them.
Until they can prove any non-trivial product of theirs can protect against moderate attackers, their claims about security of any form are extraordinary claims and thus demand extraordinary evidence (like certification proof). I am not holding my breath.
[1] https://support.apple.com/guide/certifications/ios-security-...
[2] https://support.apple.com/library/APPLE/APPLECARE_ALLGEOS/CE...
[3] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR...
[4] https://www.commoncriteriaportal.org/files/ccfiles/CC2022PAR...
Most of these one touch zero day attacks are left there for the use of intelligence agencies. They have dozens it's more just how long they stay working until some security researcher notices it and they have to publicly close that doorway.