Haifei Li

Haifei Li

@haifeili · Twitter ·

I’ve said before and saying again. This is a common problem in vendors - the lack of understandings of the importance/value of new attack vector discovery research.

Dohyun Lee

CVE-2024-23282 : A maliciously crafted email may be able to initiate FaceTime calls without user authorization I submitted a complete PoC for this vulnerability to Apple, but they awarded me a reward of $5,000. I requested a re-evaluation, but Apple declined.😢

Quoted post media Quoted post media