I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.
NR
Unrated
Apple Security Bounty
2 more reviews needed for a grade
Reported practices
+
Assigns CVEs
1 report
+
Responsive communication
1 report
+
Credits researchers
1 report
+
Clear, honest scope
1 report
Found a vulnerability?
Apple has not claimed a profile here. If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf — with your explicit permission — and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
1 publishedResponsive, fair, and quick.
★★★★★
positive
via Direct / email
reports 9
paid $500 – $2k
1st reply Within 3 days
resubmit yes
+ Assigns CVEs
+ Clear, honest scope
+ Credits researchers
+ Responsive communication
Log in to comment