Fixing isn’t the identical as securing
As a substitute of merely checking whether or not the fastened code compiled or handed automated exams, 1Password mentioned it reviewed each generated repair for full elimination of the vulnerability, preservation of utility habits, and avoidance of latest safety dangers.
Whereas solely 26% of the patches efficiently fastened the vulnerability with out introducing utility adjustments, 49.3% didn’t take away at the very least one exploitable assault path, 2.3% fastened the unique vulnerability however launched a brand new one, and a pair of.2% each didn’t remediate the problem and created an extra safety weak point.
The researchers additionally discovered that passing pre-defined exams can create deeper issues. Multiple-third of the patches that originally appeared profitable had been categorised as “fragile” as a result of they merely blocked the proof-of-concept (POC) exploit used throughout testing as an alternative of addressing the underlying root trigger.


