Early access: the directory is still filling out, and every rating here is a reported experience.

Researcher review

Authentication Bypass on *.apple.com
positive

Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel sluggish compared to standard bug bounty platforms, the Apple Security Team was professional once communication opened up regarding the remediation and potential bounty rewards. The highlight was working through the remediation phase and actively verifying the fix once they patched the flaw. For other researchers targeting Apple: rely heavily on manual testing and business logic over automated scanners, document your reproduction steps flawlessly, and don't be afraid to politely ping them for updates while you wait.

reports 1 1st reply 1–3 months resubmit yes recommends yes skill Intermediate
+ Assigns CVEs + Clear, current policy + Clear, honest scope + Credits researchers − Slow to pay − Slow to first response
Rathore · Aug 8, 2026 · Share ↗ 2 helpful

Share this review

Share on X Share on LinkedIn