3 ms·
Weird thing to see at number 3 on HN - is there some subtle context I am missing here? Are we wink winking that it's a lot of fixes?
by AJRF 2mo ago
Weird thing to see at number 3 on HN - is there some subtle context I am missing here?
Are we wink winking that it's a lot of fixes?
- croemer 2mo agoI think that's it?
- DStiego 2mo agoRelevant context might be for example that there are 4 mentions each of Claude by Anthropic and XGPT by ThreatBook, both based on LLMs. AI attribution might be one reason people are particularly curious.
- AJRF 2mo agoI missed that, thanks for pointing out
- grahamlee 2mo agoAnd it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: An access issue was addressed with additional sandbox restrictions." This references CVE-2026-43819, which doesn't have any more information. Compare this with the nearly decade-old https://support.apple.com/en-gb/103680 https://support.apple.com/en-gb/103680, and you see much more specific information about problems and their remedies (except in situations where Apple's action was to update a vendor component).
- Gigachad 2mo agoThe vagueness could be intentional. There’s been a big issue with linux where proof of concept exploit code gets posted before the bug is announced because people reverse engineer it from the fix commits. Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.
- eviks 2mo ago> before it was ever used. But since this is never known, does the user need to know?
- acdha 2mo agoRemember that they have a great deal of telemetry around things like crashes and work with groups like Citizen Lab for certain high-risk users. You can’t prove that something was never used in a perfectly targeted and concealed attack but it’s likely they can say it wasn’t used outside of such contexts, and once you’re at the level of things like “the Mossad deployed an exploit after configuring the local cell tower to drop external network access before crash reporter could phone home” user notifications in the release notes aren’t effective anyway.
- Tepix 2mo agoYes, it's really quite a lot https://9to5mac.com/2026/07/27/ios-26-6-fixes-over-75-security-issues-with-your-iphone-update-now/ https://9to5mac.com/2026/07/27/ios-26-6-fixes-over-75-securi...
- cromka 2mo agoI think it's because it's the first big batch of fixes found at Apple by Mythos.
- nozzlegear 2mo agoIs this speculation? Where does it say Mythos was responsible for any of this?
- cromka 2mo agoIt is speculation, which is what I think the upvote count reflects.
- microtonal 2mo agoIt is a lot of fixes and the Android Security Bulletins of June and Android 17 also had a lot of fixes [1], despite ASBs only containing high/critical vulnerabilities (other vulnerabilities are only fixed in major releases and QPRs, which most Android vendors respectively roll out late or never at all). I think the story here is that vulnerability discovery has accelerated a lot with LLMs, but since are adversaries are doing the same, it is more important than ever to update quickly (and not let some Android vendors get away with their lazy update schedules). [1] https://source.android.com/docs/security/bulletin/2026/2026-06-01 https://source.android.com/docs/security/bulletin/2026/2026-... https://source.android.com/docs/security/bulletin/android-17 https://source.android.com/docs/security/bulletin/android-17
- cubefox 2mo agoSo using newish phones that don't get updated anymore could be a lot more dangerous now than it was just a year ago.