Hacker News new | past | comments | ask | show | jobs | submit login

So are we going to take this twitter post at face value? Anyone have more info?

Yes, it's literally the first item in the iOS 17.5 security release notes: https://support.apple.com/HT214101

Yep, that was in the tweet. Got any more info about the exploit or why it’s not in their categories?

I presume some in the list did received bounties?

Here are the categories: https://security.apple.com/bounty/categories/

I'm not really sure what else you're asking for. Nobody in the world except Apple Product Security itself knows why Apple Product Security is refusing to pay a bounty in this case. It makes no sense.

Well. He knows more about the exploit. Maybe he could tell us what it is.

Updated from his twitter: apple apparently confirmed i am right and that it’s not exploitable in real user software. Still outraged?

I literally saved the link to this story in my "look again in a couple days" folder, and lo and behold, the story makes sense again.

Yep. It explains why he didn’t get paid.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
