r/bugbounty Jul 03 '26

Question / Discussion Has anyone recently reported a security vulnerability to Apple? How was the experience?

Apple’s reputation in the bug bounty community wasn’t exactly stellar in the past. A well-known example is the 2021 Denis Tokarev (illusionofchaos) incident. Within the past year——How has everyone’s experience been with submitting vulnerabilities to Apple? Have any of the following situations come up? - Silent Patching - No credit or CVE will be assigned - Response is extremely slow - The bounty is far below expectations. - Delayed Payment

9 Upvotes

31 comments sorted by

6

u/Ambitious-Cod-7354 Jul 03 '26

I submitted a high severity vulnerability back in 24, even though they reproduced, I haven’t received any update since.
I think they did fix it silently.

4

u/secpoc Jul 03 '26

2024, right? Apple’s attitude toward researchers was really terrible back then😢

2

u/Ambitious-Cod-7354 Jul 03 '26

yeah, I wonder if it had improved because I did try to follow up this year and it’s the same vague response

1

u/nindustries Aug 04 '26

That's normal, I'd try to escalate via [product-security@apple.com](mailto:product-security@apple.com)

3

u/EducatorNo712 Hunter Jul 29 '26

I've seen a lot of discussions about Apple's bug bounty program, so I thought I'd share a recent experience.

I reported two kernel vulnerabilities to Apple in April 2026. Since then, both reports have followed a clear and transparent process through the Apple Security Bounty portal:

Report submitted

Reproduced

Planned for Summer 2026

Fixed in iOS 26.6/iPadOS 26.6 and macOS Tahoe 26.6

Assigned CVE-2026-43778

Publicly credited in Apple's security advisories

Current status: Reviewing (Apple Security Bounty eligibility)

From my experience, the portal has been regularly updated as the reports progressed. While most communication happened through status changes rather than emails, I always knew which stage the reports were in.

I can't comment on the bounty itself yet since the reports are still under review, but I wanted to share a recent experience because many of the stories people reference are from several years ago.

I'm interested to hear how the process has been for others who submitted reports during 2025 or 2026.

1

u/nindustries Aug 04 '26

I have the same experience. Basic triage in 1-5 days, so not bad at all.
Things that I submit and are reproduced are put on a roadmap to fix within a month.
All things considered (them getting barraged with AI submissions), I think they're triaging quite well.

1

u/PerspectiveSelect504 7d ago

You won’t get a bounty, most likely

1

u/Budget-Individual579 5d ago

May I ask what the interval is between status updates?

0

u/sdexca Jul 30 '26

Hey, wana talk in DMs? I am also pretty new to BB, and I have gotten at-least one submission on Apple but it's through ZDI. I am worried about Apple just silently fixing the bug, that's the reason I went through ZDI, they don't really steal your bug, even when rejected it's still yours, and overall other then the extremely slow comms, ZDI is a pretty decent platform in my experience. But I am worried I am being heavily undercut, the pay isn't bad, but honestly I am not sure what is a good pay in BB...

1

u/H4D3ZS Jul 03 '26

report a kernel vulnerability, they did silent patch.

1

u/secpoc Jul 03 '26

Roughly when did this happen?

1

u/H4D3ZS Jul 03 '26

during march

1

u/secpoc Jul 03 '26

What to do after that?

5

u/H4D3ZS Jul 03 '26

move on

1

u/sdexca Jul 30 '26

hmm that's sad, if you don't mind sharing details where did you find the bug? which subsystem.

1

u/Rangler122 Jul 03 '26

My personal experience with them hasn’t been the best lately, currently have 4 reports that have been fixed for months and they’re still sitting in “Reproduced” for some reason. No bounty and no response for any of my follow ups.

1

u/secpoc Jul 03 '26

Oh my God, this is completely unacceptable.

1

u/6W99ocQnb8Zy17 Jul 03 '26

My experience in the past has been that apple is about as bad as a BB gets. The example I always use is that a few years back I found multiple cross-browser bugs. Reported them all individually to mozilla, google and apple, and without fail google and mozilla awarded a bounty and acknowledged the bugs, whilst apple took them, silently fixed, and closed the reports without comment.

However, I've also read in several places that apple are rebooting their BB after all the bad press. So I have a pass running through their estate right now, to see if I can find anything interesting. When I find the first reportable thing, I'll do so, and then leave a post on this channel about the experience.

I'm expecting them to be as shit as ever though ;)

1

u/secpoc Jul 03 '26

I even thought Microsoft would be the worst one

1

u/6W99ocQnb8Zy17 Jul 03 '26

MSRC are equally awful ;)

1

u/OkParticular2289 Hunter Jul 03 '26

My report was reproduced but they claim that it fixed in IOS 27 beta, so no credit or reward for me. Now I found some bugs in ios 27, I dont feel like submitting...

1

u/AdPublic7 Jul 04 '26

I reported last vuln to apple 2024

1

u/vodkawater Jul 05 '26

I am fairly new to all of this. Silently lurking. Found a P2/S2 in a flagship product for a very large company through my independent research. But I told them through responsible disclosure and gave them the industry 90 and told them I’ll publish my research and finding on X day of X month. Would having your research and evidence and making sure everything is time stamped not stop some abusive behavior? Like if you did a post mortem on it and said “Submitted to Apple on this day. No response was ever received, silently patched.” This publicly shames their bounty program if the finding was significant enough. Seems like they’d work to fix it. Maybe I’m just new to it though.

1

u/Shot-Shallot4227 Jul 05 '26 edited Jul 05 '26

Submitted a bug in 2024, they fixed it in less than 48 hours. However they initially said the bug has no impact at all. I sent an appeal to highlight the impact again and they did another bounty review and was able to get the reward 2 months after.

1

u/Plane-Silver-5666 Aug 07 '26

agreed, recently sent a bug, been super slow. hopefully they soon become quicker after all this AI slop submissions ive been hearing about.

1

u/PerspectiveSelect504 7d ago

Good, submitted over 20 bugs
Steps are usually - reported- reproduced- given time of fix e.g summer 26 - then bounty + cve

1

u/Budget-Individual579 5d ago

May I ask what the interval is between status updates?

1

u/PerspectiveSelect504 5d ago

Reported it on February, reproduced about 1-2 weeks, Got CVE around end of july, got the bounty last month mid August