Skip to main content
AppleCybersecurity incident

Apple is the subject of a confirmed 0-click Denial of Service (DoS) vulnerability disclosure in iMessage, discovered by security firm IronPeak and assigned a CVE.

What happened

Post: "EX-ARRR: Sailing the Apple 0-click Seas"

Source

RedditSep 26, 2026By u/nindustries

r/netsec

EX-ARRR: Sailing the Apple 0-click Seas

upvotes
32
comments
11

Extracted from these lines

  • [comment u/No-View3333] Was code execution achieved in the actual iMessage-triggered daemon, or only in the test harness?

  • [comment u/buherator] Note that the assigned CVE entry classifies this as a DoS

reddit.com/r/netsec/comments/1wqmb3o/exarrr_sailing_the_apple_0click_...Open the source

Comments on the post

5 of 11 comments
  • “honest caveat: the load-bearing seam makes this post insufferable to read”

    u/SirensToGo20 points · Sep 26, 2026View

  • “God, AI writing is so hard to read. If I see the word “honest” one more time…”

    u/rob9470819 points · Sep 26, 2026View

  • “Was code execution achieved in the actual iMessage-triggered daemon, or only in the test harness?”

    u/No-View33335 points · Sep 26, 2026View

  • “No mention of bounty? Curious.”

    u/petermal673 points · Sep 26, 2026View

  • “Note that the assigned CVE entry classifies this as a DoS”

    u/buherator1 points · Sep 28, 2026View

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/netsec
Stage
Confirmed
Event date
Sep 2026

The full record

From the Signal API record

Numbers

Mentions
23

Details

Timing
Completed
Category
Vulnerability disclosed
Link URL
ironpeak.be
Virality
Somewhat high
Post kind
Link
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • cybersecurity
  • vulnerability disclosure
  • denial of service
  • mobile security
  • 0-click

Products named

  • iMessage

Extraction

Sentiment
Negative
Detected
Sep 26, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for Apple and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Apple this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/e3e20231-2905-5d9e-abea-1a775695e55a returns this record as JSON. POST /v1/companies/enrich returns every signal for apple.com.

{
  "signal_id": "e3e20231-2905-5d9e-abea-1a775695e55a",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-09-26T09:35:39+00:00",
  "company": {
    "name": "Apple",
    "domain": "apple.com"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "cybersecurity",
      "vulnerability disclosure",
      "0-click",
      "denial of service",
      "mobile security"
    ],
    "post_id": "1wqmb3o",
    "summary": "Apple is the subject of a confirmed 0-click Denial of Service (DoS) vulnerability disclosure in iMessage, discovered by security firm IronPeak and assigned a CVE.",
    "category": "vulnerability_disclosed",
    "comments": [
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wqmb3o/comment/pc7pbpk/",
        "depth": 0,
        "score": 20,
        "author": "SirensToGo",
        "excerpt": "honest caveat: the load-bearing seam makes this post insufferable to read",
        "posted_at": "2026-09-26T18:02:45.000Z",
        "author_url": "https://www.reddit.com/user/SirensToGo/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wqmb3o/comment/pc75q96/",
        "depth": 0,
        "score": 19,
        "author": "rob94708",
        "excerpt": "God, AI writing is so hard to read. If I see the word “honest” one more time…",
        "posted_at": "2026-09-26T16:36:43.000Z",
        "author_url": "https://www.reddit.com/user/rob94708/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wqmb3o/comment/pc5cnbu/",
        "depth": 0,
        "score": 5,
        "author": "No-View3333",
        "excerpt": "Was code execution achieved in the actual iMessage-triggered daemon, or only in the test harness?",
        "posted_at": "2026-09-26T10:56:06.000Z",
        "author_url": "https://www.reddit.com/user/No-View3333/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wqmb3o/comment/pc9bkwi/",
        "depth": 0,
        "score": 3,
        "author": "petermal67",
        "excerpt": "No mention of bounty? Curious.",
        "posted_at": "2026-09-26T22:32:45.000Z",
        "author_url": "https://www.reddit.com/user/petermal67/"
      },
      {
        "url": "https://www.reddit.com/r/netsec/comments/1wqmb3o/comment/pcj7zdp/",
        "depth": 0,
        "score": 1,
        "author": "buherator",
        "excerpt": "Note that the assigned CVE entry classifies this as a DoS",
        "posted_at": "2026-09-28T07:52:50.000Z",
        "author_url": "https://www.reddit.com/user/buherator/"
      }
    ],
    "evidence": [
      "[post] EX-ARRR: Sailing the Apple 0-click Seas",
      "[comment u/No-View3333] Was code execution achieved in the actual iMessage-triggered daemon, or only in the test harness?",
      "[comment u/buherator] Note that the assigned CVE entry classifies this as a DoS"
    ],
    "link_url": "https://ironpeak.be/blog/ex-arrr-sailing-the-0-click-seas/",
    "virality": "somewhat_high",
    "post_date": "2026-09-26T09:35:39.000Z",
    "post_kind": "link",
    "sentiment": "negative",
    "subreddit": "netsec",
    "event_date": "2026-09",
    "post_title": "EX-ARRR: Sailing the Apple 0-click Seas",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/netsec/comments/1wqmb3o/exarrr_sailing_the_apple_0click_seas/",
    "entity_role": "subject",
    "post_author": "nindustries",
    "upvote_ratio": 0.8636363636363636,
    "mention_count": 23,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/netsec/",
    "total_upvotes": 32,
    "comments_total": 11,
    "total_comments": 11,
    "post_author_url": "https://www.reddit.com/user/nindustries/",
    "signal_category": "event",
    "comments_included": 5,
    "products_mentioned": [
      "iMessage"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.