I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.
Researcher review
Responsive, fair, and quick.
★★★★★
positive
via Direct / email
reports 9
paid $500 – $2k
1st reply Within 3 days
resubmit yes
recommends yes
skill Advanced
+ Assigns CVEs
+ Clear, honest scope
+ Consistent decisions
+ Credits researchers
+ Engages on the technical detail
+ Respectful & professional
+ Responsive communication
− Slow to pay
Report-by-report detail
remoted leaks device private key + identity from system keychain without entitlement check
Resolved High
bounty $500 – $2k
ref OE11052766702612
The security team addressed the issue in all planned releases. This report was listed under Additional recognition in the following advisories: support.apple.com/128067
Share this review