Go write your own memory safe curl if one _actual_ vuln in 10 years is not within your risk appetite.
Go write your own memory safe curl if one _actual_ vuln in 10 years is not within your risk appetite.
Why hasn't Apple rewritten libtiff, libpng, libjpeg, libwebp, et c in Swift?
Their flagship moneymaker keeps getting popped via these, and they have thousands of engineers and a memory safe first party language. The zeroclick from a few weeks ago relied on a chain, the second most important of which (CVE-2023-41064) was in libwebp. (The first most important was a kernel privilege escalation. XNU is c and cpp, of course.)
I really can't imagine that writing performant replacements for these libraries would be that daunting a task for them, and it would permanently shut down an entire class of repeated, ongoing vulnerabilities. I really don't understand why Apple relies on 3p code for format parsing/decoding when it has proven over and over again to be a source of brand damage.
Curl is maintained by a much smaller set of people, and is delivered for free.
Because they're shared libraries which other programs have linked to.
Additionally they've had decades of work and rewriting them increases chance that it will break something.
They also use them in Safari, AFAIK.
I'm also pretty sure most consumers of them are using them via ImageIO, which is under Apple's exclusive control.
It's almost always apple's own iMessage app that gets compromised; so they can use whatever library they want.
Also apple can be slow to write things in new coding languages internally, there is a lot of stuff still in Objective-C and will be for many, many years.
If we’re gonna start somewhere when it comes to memory safety, I assume fixing adobe acrobat would have a better ROI.