top | item 23381675

Apple patches CVE-2020-9859 (unc0ver)

190 points| rowawey | 5 years ago |support.apple.com

74 comments

order
[+] saagarjha|5 years ago|reply
I think this might be the fastest patch of a security issue affecting Apple's operating systems, ever. Aside from *.0.1 releases that fixed critical bugs with core features in new OSes, has anything been patched this fast?

(I'm also obligated to post that the bug that this fixes is not new; it was discovered back in iOS 11, fixed, and Apple reopened it in an iOS 13 update: https://www.synacktiv.com/posts/exploit/return-of-the-ios-sa...)

[+] saurik|5 years ago|reply
I have a pretty clear memory of the JailbreakMe 2/3 bugs (which, for anyone else reading, were bugs that could be used from the web browser, and so were of the form "you click a link or have some evil iframe and are pwned") being fixed in six days (which I mentally cataloged as the minimum turnaround time Apple could muster).
[+] prvc|5 years ago|reply
If that doesn't illustrate their true priorities re: user security/ privacy, then I'm not sure what could.
[+] Wowfunhappy|5 years ago|reply
From the equivalent macOS patch: https://support.apple.com/en-us/HT211215

> Available for: macOS High Sierra 10.13.6, macOS Catalina 10.15.5

That's interesting—did the bug exist on both 10.13 and 10.15, but not 10.14?

[+] 0x0|5 years ago|reply
If it is true the bug was present in iOS 11 and fixed in iOS 12 before being reintroduced in iOS 13, that might align with macOS 10.14 (≈ iOS 12) being unaffected.
[+] saagarjha|5 years ago|reply
Yes: it was fixed for that period and then rebroken for Catalina.
[+] vmchale|5 years ago|reply
Oh dear. My laptop is saying 10.15.4 is the latest. Huh.
[+] xerces8|5 years ago|reply
So, it is a bug in macOS or iOS? Both?
[+] baggy_trough|5 years ago|reply
Be nice if they could patch a kernel bug in macOS with less than a 1.5GB download.
[+] jmull|5 years ago|reply
It might seem strange, but they are using a change/build/deploy mechanism designed to deliver updates to any and all parts of an OS across a range of hardware devices.

I'm pretty sure the mechanism, from end-to-end, is complex, and providing an optimized path for small changes would require resources, introduce more risk, and come at the expense of something else.

Sucks, though, for everyone who doesn't have a reasonably fast or reliable internet connection.

[+] tuxone|5 years ago|reply
On my iPhone SE 2020 the update size is 3,31 GB (from 13.5 to 13.5.1)
[+] xerces8|5 years ago|reply
at least the iOS patch is "only" 44 MB
[+] myko|5 years ago|reply
I jailbroke for the first time in nearly a decade when unc0ver came out. It's actually pretty useful. I really love having the ability to use Flex on any app on my device.
[+] mangix|5 years ago|reply
Phew. Just updated to 13.5. Good to know I'm good on the jailbreak front.