← Home ← Back to /g/

Thread 106346910

40 posts 20 images /g/
Anonymous No.106346910 >>106348477 >>106349854 >>106349995 >>106350232 >>106353288 >>106355865 >>106356126 >>106356193 >>106358154 >>106360752 >>106363028 >>106363674
wake up, babe! new apple backdoor just dropped!
>"iOS 18.6 - Undocumented TCC Access to Multiple Privacy Domains via preflight=yes"
https://github.com/JGoyd/Undocumented-System-Behavior-in-iOS-18.6-Silent-TCC-Bypass-and-Data-Movement
https://seclists.org/fulldisclosure/2025/Aug/5

>Covert access to biometric, microphone, calendar, and contact data
>Not visible or controllable via Privacy Settings
>User cannot audit, deny, or revoke this access
>Suggests behavioral profiling or device telemetry below user awareness
>Potentially violates GDPR/CCPA data processing regulations
Anonymous No.106347643 >>106347669 >>106354239 >>106356153 >>106356193
iTODDLERS BTFO
Anonymous No.106347669
>>106347643
basiert
Anonymous No.106347670 >>106352696
LOL WOWIES LOL SHOULD HAVE BOUGHT A PIXEL AND INSTALLED GRAPHENEOS LMAO!
Anonymous No.106348477 >>106349238
>>106346910 (OP)
>The Anti GOS shill isn't spamming in this thread
Weird how he's ignoring this one, isn't it?
Anonymous No.106349238
>>106348477
probably the anon as the apple poster that rages about not being indian, used to post the same 2 or so images over and over again until anons started documenting his mental illness.
Anonymous No.106349854 >>106350545
>>106346910 (OP)
so... an old OS version has an exploit? something that already got patched?
whoa I'm switching to android
Anonymous No.106349995
>>106346910 (OP)
...but where's the exploit?
"apple can transfer data and you can see it in logs if you have physical access to the unlocked device" isn't exactly unexpected behavior
Anonymous No.106350232 >>106350545
>>106346910 (OP)
Wake up, babe! New fake ChatGPT-written """advisory""" just dropped! The other repos have shady PDFs instead of PoCs, and the Python scripts are hallucinated nonsense. Very legit!
Anonymous No.106350494 >>106350545 >>106366503
Now watch this get memory holed or coped into normalcy
Anonymous No.106350545 >>106351333 >>106353288 >>106353288 >>106355418
>>106349854
>already got patched
yes, after this jewish man found the backdoors.
>old
this os version tsn't old. this version was released in july 2025. the update to patch this shit was 3 days ago.

>>106350232
> ramashit not coping at all

>>106350494
it's not like how it was years ago. these things now get a lot more attention
Anonymous No.106351333
>>106350545
>it's not like how it was years ago. these things now get a lot more attention
Yeah, uh. Quite the outrage ITT.
Thought with so many apple fanboys it would be full of discussion haha.
Anonymous No.106352696
>>106347670
this but unironically
Anonymous No.106353288 >>106355467
>>106346910 (OP)
Is it real? Looking around online it seems it might be faked with AI, and no one else has confirmed it... the same researcher wrote about a bluetooth vulnerability in a previous iOS version that also got no coverage or corroboration and also was claimed by others to be fake.
>>106350545
>the update to patch this shit was 3 days ago
I think from what I can see at least publicly, Apple has not patched this or even acknowledged it.
>>106350545
>these things now get a lot more attention
You'd think so, wouldn't you?
Anonymous No.106353638
"modern" apple has that distinct facebook boomer aura now
it's unironically over for them.
Jobs knew how to keep their image at the forefront.
Anonymous No.106354239
>>106347643
bastiat
Anonymous No.106355418 >>106355467
>>106350545
Not even orangesite accepts this slop. The vulns are fake, just because you put some daemon names in bold and write "CVSS 9 Preliminary Critical" does not make you LE EPIC HAXXOR!!
Anonymous No.106355467 >>106356057
>>106353288
>Is it real?
it's real. you can try it yourself if you have an imolestor device and ipajeetbook

>>106355418
> seething this hard
> orange reddit
shitting street: designated and overflowing
Anonymous No.106355865
>>106346910 (OP)
>they found the mossad backdoor
I KNEEL
Anonymous No.106356057
>>106355467
This does not look like truth to me; and most, if not all, people have not ever believed your posts. All you can do is post shitty jeet macros.

There are more things which you are hiding than answering truthfully, especially considering that I have spotted you on multiple sockpuppet accounts on Reddit and HN reposting the same thing over and over again. Using AI for majority of your posts and comments shows that you are being lazy.

Why is CVE-2025-31200-iOS-AudioConverter-RCE (May 2025) a plagiarized work of https://github.com/zhuowei/apple-positional-audio-codec-invalid-header (April 2025) where the original creator was credited in CVE-2025-31200?

And in your previous posts: you mentioned that on your personal iPhone, Apple was sending data to their own servers and you ended up listing a private (localhost) IP address which no one has access to? Why is that?
Anonymous No.106356126
>>106346910 (OP)
could be also to secure you're data
Anonymous No.106356153
>>106347643
basko
Anonymous No.106356193 >>106358123
>>106346910 (OP)
Anon, but that's nothing new, backdoors are everywhere just accept that and live with that.
Societal order is literally ducktapped together with backdoors.
Privacy is dead anon, get over it.

>>106347643
AYY LMAOOOOO ANON ACTUALLY THINKS THERE'S NOTHING LIKE THAT IN HIS JETDROID AHAHAHAHHAHAHAHAHAHAHAHAHHAHA
AHAHAHAHAHAHAHAHHAHAHAHAHAHAHAHAHAHAHHAHAHAHAHAHAHAHAHAHAHAHAH
(I don't own any apple devices)
Anonymous No.106358029 >>106363001 >>106364910 >>106365038 >>106366360 >>106367283
iTODDLERS BTFO
Anonymous No.106358123
>>106356193
link a public one retard
Anonymous No.106358154 >>106358504
>>106346910 (OP)
Anonymous No.106358504
>>106358154
kek
Anonymous No.106360752
>>106346910 (OP)
Do people realize that Apple is a PRISM partner or did everyone just forget about that?
Anonymous No.106363001
>>106358029
bass
Anonymous No.106363028 >>106363511
>>106346910 (OP)
only the most evil people on planet earth want to antisocialize iphone users.

pure raw serial killer evil.
Anonymous No.106363511
>>106363028
schizo post
Anonymous No.106363674 >>106368074
>>106346910 (OP)
TCC doing preflight on core domains isnโ€™t new, doing it with client_dict=null across FaceID/mic is. Looks like a policy probe layer, not data pull. Appleโ€™s line will be โ€œcapability check,โ€ but the breadth + repetition screams telemetry gating.
If you want to see it without USB, enable sysdiagnose and grep com.apple.TCC in the tar. Cross-check with tccd and the usual suspects: biometrickitd, mediaserverd, proximitycontrold. Watch for paired spikes in aggregatedd.
Mitigations right now:

kill background analytics: defaults write com.apple.SubmitDiagInfo AutoSubmit -bool false (Mac side MDM profile for iOS), nuke Significant Locations, disable Siri suggestions.
block trustd/apsd/analyticsd on Wi-Fi with a DoH firewall profile. Youโ€™ll lose push. Tradeoff.
Short term: Lockdown Mode reduces some daemon surfaces. Airgapped Focus + no Face ID = fewer preflights observed.
If this is ATT/usertracking preflight, EU regulators will have a field day. Save your logs, hash them, timestamp with opentimestamps. If Apple says โ€œexpected behavior,โ€ ask them for the DPIA.
Anonymous No.106364910
>>106358029
basted
Anonymous No.106364950 >>106366440 >>106368074
Apple patched this in one day while jeetdroid gets security patches in 3 years
Anonymous No.106365038
>>106358029
bingo
Anonymous No.106366360
>>106358029
told them
Anonymous No.106366440 >>106368074
>>106364950
apple didn't patch this.
nor did anyone prove that system level daemons having system access is a security issue. that i can answer a phone call without having to grant any mic permission is not a security issue.
Anonymous No.106366503
>>106350494
fox btw
Anonymous No.106367283
>>106358029
belarus
Anonymous No.106368074
>>106363674
>TCC doing preflight on core domains isnโ€™t new
>>106366440
>nor did anyone prove that system level daemons having system access is a security issue
it's a big security issue. anyone being able to plug your iphone into any mac and then have access to this info, that nobody knows is there, is not a feature or you're using it wrong moment.

>>106364950
> seething street shitting sex offender can't post on /g/ any more because everyone knows who he is
nice one rajeesh. post the same 3 or so images again if you could.