Image via ID 216231196 © Wachiwit | Dreamstime.com
In a bid to enhance the security of its ecosystem, Apple
introduced the Security Bounty Program to the public in 2019.
This scheme was aimed to encourage researchers to report any critical vulnerabilities with, or techniques used to exploit, Apple’s operating systems (OS). As an incentive, payouts of up to a million dollars were offered depending on the tier of discovery, hence the “bounty.”
While this sounds like a highly effective way to encourage users to keep using the OS while attempting to discover vulnerabilities, such as the
Pegasus spyware, various reports have surfaced over the last few years that indicate that Apple isn’t doing exactly what it said it would.
In a blog post, one security researcher who prefers to remain anonymous shared their “frustrating experience” with the tech giant.
They stated that they had made four reports between March and May of this year regarding zero-day vulnerabilities, which are critical to users’ privacy.
Despite expecting the vulnerabilities to be patched up quickly, they stated that three of these are still present in the newest iOS 15, and although one was fixed, they were not credited by Apple for discovering it.
“When I confronted them, they apologized, assured me it happened due to a processing issue and promised to list it on the security content page of the next update. There were three releases since then and they broke their promise each time,” the researcher wrote.
Finally, they gave Apple an ultimatum: respond, or they’d release the research to the public. This was apparently ignored, so they went ahead to publish their findings.
One of these is a big hole in Game Center, which reportedly allows any app installed via the App Store to access user data including the Apple ID email used, the full name associated with the Apple ID, and an authentication token.
There is also an alarming opportunity for the app to be granted “complete file system read access” to the Core Duet database. This contains contacts from communications apps such as Mail, iMessage, and even third-party messaging apps.
Not only that, the user’s interactions with these contacts, such as timestamps and even some attachments, are accessible.
It’s clear to see why this needs to be fixed, yet the vulnerability apparently still lingers in iOS 15.
In the blog post, other risks are reported in detail. There are also links to various other accounts of researchers who have faced similar problems with the Security Bounty Program, such as
this.
A day after the post was initially published, Apple finally responded to the researcher, acknowledging the blog post and the reports.
“We want to let you know that we are still investigating these issues and how we can address them to protect customers,” the company wrote. “Thank you again for taking the time to report these issues to us, we appreciate your assistance.”
[via
MacRumors, image via ID 216231196 ©
Wachiwit | Dreamstime.com]