A group of hackers has received 32 payments from Apple totaling $288,500 for discovering 55 vulnerabilities (11 critical) in the core systems as they hacked the tech giant for three months.

The critical bugs allowed the group to take control of core Apple infrastructure and “from there steal private emails, iCloud data, and other private information”.

Apple promptly fixed the vulnerabilities. There were a total of 55 vulnerabilities discovered with 11 critical severity, 29 high severity, 13 medium severity and 2 low severity reports.

According to the web application security researcher Sam Curry who was part of the group, once Apple processes the remainder, the total payout might surpass $500,000.

As of 6 October, the vast majority of these findings have been fixed and credited. They were typically remediated within 1-2 business days (with some being fixed in as little as four-six hours).

The hackers targeted Apple’s web assets after reading about 27-year-old Indian security researcher Bhavuk Jain who recently won $100,000 (over Rs 75.5 lakh) from Apple for discovering a now-patched Zero Day vulnerability in the Sign in with Apple account authentication.

“This was surprising to me as I previously understood that Apple’s bug bounty programme only awarded security vulnerabilities affecting their physical products and did not payout for issues affecting their web assets,” Curry said.

Between 6 July- 6 October, Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb and Tanner Barnes worked together and hacked the company.

“If the issues were used by an attacker, Apple would’ve faced massive information disclosure and integrity loss,” Curry said.

“For instance, attackers would have access to the internal tools used for managing user information and additionally be able to change the systems around to work as the hackers intend”.

Apple has been actively investing in its bug bounty programme and security researchers can receive up to one million dollars per vulnerability depending on the nature and severity of the security flaw.

“As of now, 8 October, we have received 32 payments totaling $288,500 for various vulnerabilities,” Curry said.

“However, it appears that Apple does payments in batches and will likely pay for more of the issues in the following months”.

Curry said that Apple has had an interesting history working with security researchers, but it appears that their vulnerability disclosure programme is “a massive step in the right direction to working with hackers in securing assets and allowing those interested to find and report vulnerabilities”.

Source: https://en.prothomalo.com/corporate/global/apple-awards-288500-to-hackers-who-spot-55-bugs-in-its-systems

Apple, Vulnerability, Computer security

World news – US – Apple awards $288,500 to hackers who spot 55 bugs in its systems

En s’appuyant sur ses expertises dans les domaines du digital, des technologies et des process , CSS Engineering vous accompagne dans vos chantiers de transformation les plus ambitieux et vous aide à faire émerger de nouvelles idées, de nouvelles offres, de nouveaux modes de collaboration, de nouvelles manières de produire et de vendre.

CSS Engineering s’implique dans les projets de chaque client comme si c’était les siens. Nous croyons qu’une société de conseil devrait être plus que d’un conseiller. Nous nous mettons à la place de nos clients, pour aligner nos incitations à leurs objectifs, et collaborer pour débloquer le plein potentiel de leur entreprise. Cela établit des relations profondes et agréables.

Nos services:

  1. Création des sites web professionnels
  2. Hébergement web haute performance et illimité
  3. Vente et installation des caméras de vidéo surveillance
  4. Vente et installation des système de sécurité et d’alarme
  5. E-Marketing

Toutes nos réalisations ici https://www.css-engineering.com/en/works/


Please enter your comment!
Please enter your name here