Early access: the directory is still filling out, and every rating here is a reported experience.
AP

Self-hosted security programme

Apple

Apple does not use a third-party platform. Reports go directly to Apple Security Research and are triaged by Apple's own engineers. There is no profile to claim here, by design.

Reports are judged on demonstrated, reproducible impact. A primitive on its own is usually closed; show the whole chain on current, shipping software.

Direct How to report
In-house Triage
$5k–$2M Published range
Release notes Where credit lands

Featured write-up

Authentication Bypass on *.apple.com

“Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel slug…”

RA Rathore · 1 reports
Read the write-up ★★★★☆ · August 2026

Getting credit

Report to Apple, claim it here

Credit publishes in Apple’s own advisories, often months after the report. We index those, so it is waiting for you, including recognitions that carry no CVE and appear nowhere else.

Apple

Consumer hardware & OS · USA

apple.com →

Found a vulnerability?

Apple runs its own vulnerability reporting process. Here are your two ways to report it. We recommend the first.

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Programs