Tag Archives: bug bounty

Researcher refuses Telegram’s bounty award, discloses auto-delete bug

reader comments 52 with 44 posters participating Share this story Telegram patched another image self-destruction bug in its app earlier this year. This flaw was a different issue from the one reported in 2019. But the researcher who reported the bug isn’t pleased with Telegram’s months-long turnaround time—and an offered $1,159 (€1,000) bounty award in… Read More »

Apple forgot to sanitize the Phone Number field for lost AirTags

Enlarge / Apple’s AirTags—as seen clipped to a backpack, above—allow users to attempt to find their own device via location rebroadcast from other Apple users. If all else fails, the user can enable a “Lost mode” intended to display their phone number when a finder scans the missing AirTag. reader comments 28 with 25 posters… Read More »

Three iOS 0-days revealed by researcher frustrated with Apple’s bug bounty

Enlarge / Pseudonymous researcher illusionofchaos joins a growing legion of security researchers frustrated with Apple’s slow response and inconsistent policy adherence when it comes to security flaws. Aurich Lawson | Getty Images reader comments 88 with 56 posters participating, including story author Share this story Yesterday, a security researcher who goes by illusionofchaos dropped public notice… Read More »

Infosec researchers say Apple’s bug-bounty program needs work

Enlarge / If you don’t maintain good relationships with bug reporters, you may not get to control the disclosure timeline. reader comments 0 with 0 posters participating Share this story The Washington Post reported earlier today that Apple’s relationship with third-party security researchers could use some additional fine tuning. Specifically, Apple’s “bug bounty” program—a way companies… Read More »