|
|
|
|
|
by kevincox
1880 days ago
|
|
Why not? I meet my friends for lunch and want to send them some photos while sitting in the restaurant? This seems like a very plausible scenario and most users would not expect and would not want everyone in the restaurant to be able to see their email and phone number. |
|
The person you replied to literally said this should be fixed. I agree with them that this is nowhere near as serious as issues Apple has had before, since the attack requires physical proximity and the use of the share pane. Even then, it doesn’t give the attacker RCE privileges or anything similarly world shaking.
Should Apple fix it? Again, absolutely. No one has said otherwise.
Nothing is 100% secure, so the relative risk posed by vulnerabilities can only really be assessed with a threat model. In most threat models, this is nowhere near as bad as their “GOTO Fail” bug or any number of others over the years.
I think celebrities and VIPs are essentially the only ones whose threat models would actually be impacted by this vulnerability in a plausible way.