Since it's almost been a year and OBTSv7 is around the corner, I published the long overdue writeup for badmalloc:
https://gergelykalman.com/badmalloc-CVE-2023-32428-a-macos-lpe.html
Is there a website where I can review a companys security handling?
E.g. how long they took from initial contact to acknowledgement, bounty handling, etc?
#itsec
@fink @lapcatsoftware I don't know of any such thing
@gergelykalman cc: @shellsharks Designer Vulnerability badmalloc CVE-2023-32428