CSAM Security Issues – Apple's Security Patch for iOS 11

09/04/2021

Apple was recently accused of stalling an auto-scan by CSAM that they used to verify the security of their devices. The accusation has been made by a security expert and a member of CSAM. I will explain what happened and hopefully put the situation in perspective.

The incident arose after Apple submitted their security patch for iOS 11.

Thanks for your feedback. During the investigation of the security issue we are aware of, we will continue to take action to update our software and prevent future attacks.

Apple’s statement has led some to believe that Apple has not acknowledged the issue, although they have. I will explain why I believe Apple has ignored this, and explain why it is so important that CSAM considers this issue.

Please read my prior article on this subject and consider the importance of the issue.

Apple’s latest iOS 11. 3 update has brought some improvements to the security of their devices. This update should be in the wild already and many have already been updated to it. I also received mine. Apple claims to have updated their security patch for iOS 11. 3 and for Macs. I have not checked the results of Apple’s auto-scan before to know how many devices have received this update and to what extent is this auto-scan affected.

The reason why Apple is telling us they are going to update their security patch for their devices, is because they have said they will. This is the first public acknowledgement that Apple has acknowledged the security issues.

While it is possible that Apple may not have updated the auto-scan as well as they should as the number of device that received the update may be too low, I suspect that some of the devices that have already received this update are already at risk of exploitation. These include devices that are part of the CSAM network.

In addition to acknowledging that the auto-scan has happened, Apple has yet to put an end to the issue as they have said they will do.

“Who manages the list of CVEs”, “In general, who manages the list of CVE-IDs, the list of CVEs that are open, or the list of CVEs that are published?” A few questions about CVEs, and related CVE definitions, were discussed in the recent “What is a CVE? What is a CVE-ID? What is a CVE-ID?” thread on reddit.

This thread includes a comment from an unknown person discussing the CVE-2021-34527 post “The list of CVEs is managed by a third party (CWE).

The CWE is a CWE. It is not a “third party”, and there is no such thing. The CWE is a CWE that has been hired to manage the CVE List. The list of CVEs is managed by a third party. Who is that third party? It is a (very) small company called “CWE”, owned by a very large corporation.

