I have spent the last 4 months interacting with the Apple security response team (SRT). They have been incredibly thorough with their evaluations, informative closes are almost always accompanied by a detailed explanation as to why it is not applicable. They are fast with triage and will usually move on your report within 48 hours. The surface however, is increasingly hardened as automated security research has massively accelerated the speed at which it used to take. As such, the most critical note when submitting to Apple, always, and I mean always, prove the impact, weaponize the exploit, demonstrate the chain. If any part reads as theoretical, it will not strengthen the case for the report.
Researcher review
Responsive, fair, and quick.
★★★★★
positive
via Direct / email
reports 9
paid $500 – $2k
1st reply Within 3 days
resubmit yes
+ Assigns CVEs
+ Clear, honest scope
+ Credits researchers
+ Responsive communication
Share this review