iVerify-Nickname-Vulnerability-Report.pdf
ID: 45ecf5cd-d122-4864-92b0-fe7d2fac9c19
STIX ID: report--45ecf5cd-d122-4864-92b0-fe7d2fac9c19
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2025-06-05
Last Modified Date: 2025-06-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
iVerify discovered and analyzed a previously unknown iMessage vulnerability ("NICKNAME") in the imagent service that caused Use-After-Free memory corruption when mutable nickname dictionaries were concurrently accessed; telemetry and forensic evidence suggest targeted, zero-click exploitation against high-risk individuals in the US and EU. The issue was patched in iOS 18.3 by broadcasting immutable copies of nickname dictionaries; affected users should update immediately and high-risk users should enable additional mitigations like Lockdown Mode.
