logo

iVerify-Nickname-Vulnerability-Report.pdf

ID: 45ecf5cd-d122-4864-92b0-fe7d2fac9c19

STIX ID: report--45ecf5cd-d122-4864-92b0-fe7d2fac9c19

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2025-06-05

Last Modified Date: 2025-06-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
iVerify discovered and analyzed a previously unknown iMessage vulnerability ("NICKNAME") in the imagent service that caused Use-After-Free memory corruption when mutable nickname dictionaries were concurrently accessed; telemetry and forensic evidence suggest targeted, zero-click exploitation against high-risk individuals in the US and EU. The issue was patched in iOS 18.3 by broadcasting immutable copies of nickname dictionaries; affected users should update immediately and high-risk users should enable additional mitigations like Lockdown Mode.