Umphandi wokhuseleko ukhuphe iinkcukacha malunga ne-Apple HomeKit bug, ethi ukwala inkonzo kunokubangela kwizixhobo eziqhagamsheleneyo ze-iOS kwaye iqhubeke emva kokuqalisa kwakhona. Umphandi uthe waxela i-bug ku-Apple ngo-Agasti.
Umphandi wokhuseleko uTrevor Spiniolas, owafumanisa i-bug, ubiza umngcipheko we-Doorlock kwaye upapashe ubungqina bobungqina kwi-GitHub. I-bug ikwi-Apple ye-HomeKit API yezixhobo zasekhaya ezihlakaniphile. I-bug yenzeka xa abahlaseli beseka isixhobo se-HomeKit esinegama elide, malunga ne-500,000 yeempawu. Izixhobo ze-iOS ezithi ke ziqhagamshele kweso sixhobo ziyeke ukuphendula, nasemva kokuqalisa ngokutsha. Xa abasebenzisi ukubuyisela isixhobo iOS useto lwefektri, kodwa ke ungene kwi iCloud Iakhawunti eyayanyaniswa nesixhobo se-HomeKit, ibug iyavulwa kwakhona.
I-Spiniolas ibika ukuba nayiphi na i-app ye-iOS enokufikelela kwidatha yeKhaya le-Apple inokuqamba kwakhona izixhobo ze-HomeKit. Usetyenziso olunjalo lunokusebenzisa ukuba sesichengeni. I-Apple yazisa umda kubude bamagama e-HomeKit kwi-iOS 15.1 kwaye, ngokutsho komphandi, isenokuba yayiyi-15.0, ngoko oku akusenakwenzeka kwizixhobo ze-iOS ezisanda kuhlaziywa. Nangona kunjalo, izixhobo ze-HomeKit esele zithiywe ngokutsha zisenokuthi "zimise" izixhobo ze-iOS ezisebenzisa ezona nguqulelo zamva nje ze-iOS.
Umphandi ugxininisa ukuba kunokwenzeka ukuba ubuthathaka buya kusetyenziswa ngokudala inethiwekhi yaseKhaya kunye nokumemela abantu kuyo ngee-imeyile zokukhohlisa. I-Spiniolas ithi abasebenzisi banokuzikhusela kwi-bug ngokutyeshela izimemo kwiinethiwekhi ezingaziwayo zaseKhaya. Abasebenzisi be-iOS abasebenzisa izixhobo ze-HomeKit ngokwabo banokuzikhusela ngokuyinxenye ngokukhubaza 'Bonisa iziLawuli zaseKhaya' kwiZiko loLawulo.
U-Spiniolas uthe waxela i-bug ku-Apple ngo-Agasti 10. Ngokomphandi, i-Apple ibonise ukuba iya kuza nokulungiswa "phambi kwe-2022", kodwa kwinyanga ephelileyo yalungisa oku "ekuqaleni kwe-2022", emva koko uSpiniolas watshela i-Apple ukuba iyakwenza ibug esidlangalaleni ekuqaleni kuka 2022. Ibug ayikasonjululwa yiApple. Umphandi wayekhe waqhagamshelwana naye malunga ne-bug kwi-macOS, eyakhutshwa ngo-2019.
I-Spiniolas ikholelwa ukuba i-Apple yayicotha kakhulu ukuphendula kwingxelo yayo yokuqala. Umphandi wabelana ngee-imeyile kunye ne-Verge, apho umqeshwa we-Apple wavuma i-bug waza wacela i-Spiniolas ukuba ingashicileli iinkcukacha malunga ne-Doorlock de kube ekuqaleni kwe-2022. I-Apple ayizange iphawule esidlangalaleni malunga nokukhululwa.
I-Apple kudala igxekwa ngenkqubo yayo ye-bug bounty. Kwiinkampani ezinkulu zetekhnoloji, umgaqo-nkqubo wokubhengeza uxanduva lwe-Apple ngowona mncinci. Nangona i-Apple inikezela ngembuyekezo ephezulu, abahlaseli besimilo bebekhalaza iminyaka malunga nokulungiswa okucothayo kunye nezaziso ezibonakala ngathi ziyanyamalala kwimingxunya emnyama. sele ebhale inqaku malunga nezo ngxaki kunyaka ophelileyo.