In August, I submitted a security report via the ASR(Apple Security Research Project). The report involves a vulnerability exploitable by malicious actors, potentially granting unauthorized access to Apple ID accounts.
On Aug 31, the Apple security team validated my report, Asking me to keep conversations confidential. They confirmed the issue’s resolution through a system change. Apple asked me to evaluate whether their fix worked and said it would give me credit and other potential rewards when I evaluated and confirmed the problem was resolved.
After I made the vulnerability assessment and confirmation, I heard nothing back. Until recently, I was informed that I was ineligible for credit or other recognition because Apple obtained the vulnerability from other sources.
When I pointed out their previous commitment and their specific policies, Apple modified our conversation record and webpage Fine Print, pretending It was me who hadn’t read it carefully.
This can be verified via the Wayback machine.
(Part of the image has been redacted because Apple still considers it confidential)
Some don’t read so good:
(From the 10/31 way back page)
“Apple Security Bounty reward payments are made at Apple’s sole discretion and are based on the type of issue, the level of access or execution achieved, and the quality of the report.”
“Sole discretion” actually means something, sport.
With this post you’ve assured you will never be paid and may be sued.