5 ms·
It certainly suggests this. Full bullet: If you use the SRD to find, test, validate, verify, or confirm a vulnerability, you must promptly report it to Apple a
by usmannk 6y ago
It certainly suggests this.
Full bullet: If you use the SRD to find, test, validate, verify, or confirm a vulnerability, you must promptly report it to Apple and, if the bug is in third-party code, to the appropriate third party. If you didn’t use the SRD for any aspect of your work with a vulnerability, Apple strongly encourages (and rewards, through the Apple Security Bounty) that you report the vulnerability, but you are not required to do so.
- xondono 6y agoMaybe it’s me but what I read in that paragraph is: If you use the SRD, you are required to report any vulnerability. If you didn’t, you are not required but encouraged. It doesn’t say if you used it you aren’t eligible for reward