5 ms·
Super interesting, though I doubt they'll pay a bounty on something they've already fixed.
by languagehacker 2y ago
Super interesting, though I doubt they'll pay a bounty on something they've already fixed.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- ziddoap 2y ago>though I doubt they'll pay a bounty on something they've already fixed. CVE-2022–46723 was reported 2022-08-08 and fixed later on 2022-10-24, which the author of this post was credited by Apple for reporting.
- sgt 2y agoSo he likely got the bounty, then, or will get it. Any idea how much it is?
- ziddoap 2y agoDefinitely not received yet. >2024–09–12: Still no bounty [...]. Apples bounty payouts are ball-parked here: https://security.apple.com/bounty/categories/ https://security.apple.com/bounty/categories/
- hypeatei 2y agoRelevant section states: > Zero-click unauthorized access to sensitive data $5,000 to $500,000
- 0cf8612b2e1e 2y ago$5?!? Really incentivizing selling it on the black market.
- richardw 2y agoSurely depends on the severity. If the attacker is only able to read if you prefer dark mode from a calendar invite then nobody will pay a lot.
- 0cf8612b2e1e 2y agoI am not sure what Apple defines as “sensitive data”, but surely that would be something more tasty than user UI configuration.
- tptacek 2y agoWhich black market? Who is buying it? The reason they quote such a huge range of prices is that there is a huge range of utility across different exploits, and many of them aren't worth much at all, including some that seem ultra-powerful on the tin. Keep in mind also that the economics of bug bounties are different than those of the "black market". Bounties quote lower prices because they're offering assured payouts, often with lower exploit proof and enablement requirements. They're not actually apples and oranges.
- actionfromafar 2y agoIf only Apple had a better cash-flow situation so they could pay out more. Alas...
- saagarjha 2y agoApple generally does not pay a bounty before they fix something.