3 ms·
In all likelihood, Apple would just refuse to play ball and tell them to go ahead and sell it to someone else if they're so confident. Zerodium and other market
by fractionalhare 6y ago
In all likelihood, Apple would just refuse to play ball and tell them to go ahead and sell it to someone else if they're so confident. Zerodium and other markets already exist, and I don't think people at Apple lose much sleep over it. And you better hope you close that deal before Google Project Zero finds it independently and tells Apple for free. Plus the mere mention that a vulnerability exists in a specific piece of software may lead Apple engineers to finding and patching it before you can sell it. Give away too many details and it's burned.
People tend to vastly overestimate the economic impact of an exploited security vulnerability. A vulnerability which can be patched in a centralized manner has a low value half-life: it rapidly decreases in value over time. I would guess over 90% of active daily users of macOS already have the patch for this bug due to automatic updates. New buyers are essentially guaranteed not to have the vulnerability at all. The vulnerability would have to be absolutely catastrophic to be worth something, and in that case it would probably be used for targeted exploitation and burned after a short period of time.
Contrast with something like heartbleed, which is still around. That is a vulnerability with serious half-life and significant economic impact. The pool of available victims who can be exploited by heartbleed is nontrivial and persistent years later. Criminals will actually pay for something like that.