
iPhones , and it seems Apple isn't doing much to fix them. Security researcher Denis Tokarev claims that iPhones are still vulnerable to two zero-day vulnerabilities even after the release of iOS 15.1. What's worrying is that Apple has been aware of the vulnerabilities for at least seven months. Tokarev even went public with the vulnerabilities last month in an attempt to force Apple to take action, and the company promised to do so. But, according to the researcher, that hasn't happened yet.
See also: Apple releases iOS 14.8.1 for those who don't want to upgrade to iOS 15.1
“These two zero-day vulnerabilities have not yet been patched in iOS 15.1,” Tokarev explained. “They allow spyware apps like @Facebook and @tiktok_us to track you and obtain sensitive data without your permission.”
iOS 15.1 is the third iOS update released since Apple promised to fix the security vulnerabilities, and the ninth version of iOS since the researcher informed the company about the existence of the vulnerabilities.
See also: Apple Fitness+ available in 15 new countries from November 3

Tokarev says he initially notified Apple of three zero-day hacks between March and May: two that have yet to be patched and a third that the company fixed in iOS 15.0.2, but without mentioning the researcher or formally thanking or rewarding him. This is significant because Apple runs an official Security Bounty program that is intended to incentivize researchers to discover and report bugs to the company. But Tokarev’s revelations were not treated the way he had hoped. And he is not the only researcher to have been treated this way.
A combination of delayed fixes and mistreatment of security researchers is not the best, especially for a company that claims to be focused on user security. Given that attacks are also on the rise, Apple needs researchers on its side.
See also: Apple: Refused to repair iPhone she damaged herself?
Currently, there are two zero-day vulnerabilities that are not fixed in iOS 15.1, according to Tokarev. Apple needs to act immediately to protect its users.
Source: Forbes
