*seven* actively exploited zero-days were discovered in iOS in 2021 but we do not have "Allow Apps to access entire filesystem & memory" option. Priorities.
Tell me more about how privacy is a fundamental human right.
2 0days just patched... so if you're using iOS it's worth to update to the latest version.
Of course this is only the browser vulnerabilities: it does not fix additional kernel bugs that were most likely chained to these: arstechnica.com/gadgets/2021/0…
[2/N] If we needed another proof that we have to fix the broken mobile security permission model, here it is.
NSO's software is actually super easy to catch, but due to the lack of permissions it becomes almost impossible at scale, and NSO only has a single vendor to avoid.
[3/N] This was easy to do for NSO: they simply blocked telemetry, communications, and updates to Apple/Google: and viola! They were set. The vendors had no visibility.