Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's unclear if they even reported this issue to Apple.


They reported it to Apple a long time ago, over a year I think. The problem appears to be that it's very hard to mitigate.

ETA: To be clear, this isn't me speculating. I spoke with one of the authors and asked this specific question. Apple hadn't shared the mitigation with them as of a few days ago.


Thank you. Do you know if lockdown mode / disabling JIT would mitigate the issue?


From what I’m told disabling JIT might do the job. With consequences to things breaking down.


Disabling JIT would make it substantially harder to exploit.


From the site (perhaps it was updated to include this?):

> We disclosed our results to Apple on September 12, 2022 (408 days before public release).


Interestingly, the YouTube videos are 13 months old.


That's when they reported it to apple.


It's been reported

>At the time of public release, Apple has implemented a mitigation for iLeakage in Safari

However the site gives no details on timelines or a report at all.

(edit) They have added a "When did you notify Apple?" to the FAQ.


Look at the faq


See edit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: