| ▲ | dannyw 14 hours ago | |
Yes, the timeframe does matter. An actively and easily exploited (just a port scan), and high-impact root RCE needs faster patching than one week. When there was a more user visible bug (2017, empty root password gives you root, CVE-2017-13872), Apple managed to remotely patch this across all supported macOS versions in about 26 hours + next macOS online, end to end, without user intervention or manual updates. And that was a decade ago before Apple built “rapid response security updates” | ||