3 ms·
And it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: A
by grahamlee 2mo ago
And it's not actually that much information "about the security content". For example: "Impact: An app may be able to access sensitive user data. Description: An access issue was addressed with additional sandbox restrictions." This references CVE-2026-43819, which doesn't have any more information. Compare this with the nearly decade-old https://support.apple.com/en-gb/103680 https://support.apple.com/en-gb/103680, and you see much more specific information about problems and their remedies (except in situations where Apple's action was to update a vendor component).
- Gigachad 2mo agoThe vagueness could be intentional. There’s been a big issue with linux where proof of concept exploit code gets posted before the bug is announced because people reverse engineer it from the fix commits. Apple has the advantage that they can keep everything secret for long enough for the patches to roll out. And realistically there is no reason the user needs to know the details of an exploit that was patched before it was ever used.
- eviks 2mo ago> before it was ever used. But since this is never known, does the user need to know?
- acdha 2mo agoRemember that they have a great deal of telemetry around things like crashes and work with groups like Citizen Lab for certain high-risk users. You can’t prove that something was never used in a perfectly targeted and concealed attack but it’s likely they can say it wasn’t used outside of such contexts, and once you’re at the level of things like “the Mossad deployed an exploit after configuring the local cell tower to drop external network access before crash reporter could phone home” user notifications in the release notes aren’t effective anyway.