Milan start-up uncovers $200K macOS flaw, unable to report to Apple
A Milan start-up discovered a critical macOS flaw allowing complete system takeover but couldn't report it to Apple due to a cap on vulnerability submissions. This incident raises concerns about Applโฆ
A Milan start-up claims it discovered a critical flaw in macOS that allows for a complete system takeover, but it failed to report the issue to Apple due to hitting the company's new submission cap for vulnerability reports. The start-up, which utilized AI tools like ChatGPT to identify the vulnerability, revealed that the exploit could potentially compromise user data and system integrity.
This incident highlights growing concerns surrounding the security of macOS, particularly as more users transition to remote work and rely on their devices for sensitive tasks. Apple's recent change in its bug bounty program, which implemented a cap on the number of submissions accepted, has drawn criticism from security researchers. The move aims to streamline the reporting process but may inadvertently discourage the disclosure of significant vulnerabilities, as seen in this case.
The Milan start-up estimated the flaw to be worth around $200,000, the amount typically awarded for critical vulnerabilities. However, due to the cap, they were unable to submit their findings before the deadline. This raises questions about the effectiveness of Apple's current vulnerability management strategy and whether it balances incentivizing researchers with ensuring robust security for its users.
Looking ahead, it is crucial for Apple to reassess its submission policies to encourage timely reporting of vulnerabilities. If researchers feel stifled by caps, major flaws may go unreported, putting users at risk. As cyber threats continue to evolve, fostering a collaborative relationship with the security community will be key to safeguarding macOS and maintaining user trust.
Read Full Story at Decrypt โ

