Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • iPhone iOS 9/10/11 source code have been leaked on GitHub
  • Technology

iPhone iOS 9/10/11 source code have been leaked on GitHub

Do Son February 8, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

According to Motherboard and Redmond Pie reported that the iOS system source code used by the Apple iPhone has recently been someone leaked to GitHub. After analysis, people found that this part of the source seems to be related to iBoot (to ensure that the iOS operating system trusted boot this part). In fact, as early as a few months ago, someone had already been shared on Reddit. Just moving it to GitHub appearance again, aroused more people’s attention.

 

Foreign media Motherboard was confirmed after consulting security experts, this iBoot code seems to be legal, and it seems to belong to a version of iOS 9.

Although it does not really matter with the iOS 11.2.5 version currently in use, some of the code in iOS 9 may still exist in iOS 11.

However, we do not have to be too scared, after all, the newer iOS devices have been protected by the “Secure Enclave.”

 

https://twitter.com/Apple_External/status/960993190584123393

In addition, GitHub leaked part of the lack of source code, it can not be completed. However, Twitter security experts said hackers and security personnel are expected to dig out loopholes in the iOS system and create jailbreak programs.

In addition to the iBoot code, the leaked information includes a document directory that provides additional information about the iBoot. Redmond Pie noted that this helps to easily find the bootrom vulnerability for the jailbreak for iPhone/iPad.

In recent years, Apple has partially opened up macOS and iOS, but iBoot has been the company’s carefully confidential content. Motherboard said Apple’s own loophole bounty program will pay up to $200,000 to people who spot vulnerabilities that safely launch firmware.

Source: MacRumors

Related coverage

  • ASUS Urges Windows 11 Upgrade: The Dawn of AI-Powered PCs and the End of Windows 10
  • WSL Containers Windows 11: Native Linux Orchestration
  • SUSE developers propose to replace AWK with Python in the GCC compiler
  • Privacy First: Google’s AI Detects Fraud, No Cloud Storage
  • Why the U.S. Government Is Buying a Stake in Intel
  • Cloudflare’s 1.1.1.1 DNS Suffers Global Outage Due to Internal Configuration Error
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: iOS 9/10/11 source code

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105778CVSS 9.4
    A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of...
    📅 Updated: Oct 6, 2026
  • CVE-2026-94293CVSS 9.3
    An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all...
    📅 Updated: Oct 6, 2026
  • CVE-2026-56662CVSS 9.6
    GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51922CVSS 9.8
    agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51915CVSS 9.8
    TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool...
    📅 Updated: Oct 6, 2026
  • CVE-2026-51898CVSS 9.8
    sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
    📅 Updated: Oct 6, 2026
  • CVE-2026-51906CVSS 9.1
    In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers...
    📅 Updated: Oct 6, 2026
  • CVE-2026-96659CVSS 9.1
    A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.