FBI Gave First Security Disclosure Under 'Vulnerability Equities Process' to Apple on April 14 - MacRumors
Skip to Content

FBI Gave First Security Disclosure Under 'Vulnerability Equities Process' to Apple on April 14

by

iphone_4s_2015-250x300On April 14, the FBI informed Apple of a security flaw in older versions of iOS and OS X, its first vulnerability disclosure to Apple under the Vulnerability Equities Process, reports Reuters, citing information obtained directly from the Cupertino company.

The Vulnerability Equities Process allows federal agencies to determine whether critical security flaws should be kept private for law enforcement use or disclosed to companies to allow them to patch major vulnerabilities.

The security flaw the FBI shared with Apple pertained to older versions of the iPhone and Mac and it was fixed with the release of iOS 9 and OS X El Capitan. It was not the vulnerability that was exploited to break into the iPhone 5c used by San Bernardino shooter Syed Farook, which remains under wraps.

Apple says 80 percent of iPhones run a safe version of iOS and are not vulnerable to the security flaw shared by the FBI. Apple told Reuters it does not have plans to issue a patch for the older, vulnerable software.

According to Reuters, the FBI was motivated to provide Apple with information on an older vulnerability following a report suggesting it would not use the Vulnerability Equities Process to provide Apple with the method used to hack the San Bernardino iPhone.

The day after that report, the FBI offered information about the older vulnerabilities to Apple. The move may have been an effort to show that it can and does use the White House process and disclose hacking methods when it can.

The flaw the FBI disclosed to Apple this month did nothing to change the company's perception that the White House process is less effective than has been claimed, said an Apple executive who declined to be named.

Earlier today, a report from The Wall Street Journal suggested the FBI has decided not to disclose the vulnerability used to access the San Bernardino iPhone. FBI Director James Comey has insinuated the FBI cannot provide details on the hacking method used on the iPhone because the security flaw exploited is owned by a private company.

Note: Due to the political nature of the discussion regarding this topic, the discussion thread is located in our Politics, Religion, Social Issues forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Top Rated Comments

MyMacintosh Avatar
131 months ago
This is like beating up someone, and then being "nice enough" to let them know their shoes are untied
Score: 3 Votes (Like | Disagree)
Robert.Walter Avatar
131 months ago
>offering a tip that benefits less than 10% of Apple's installed base, a flaw that Apple itself has declined to bother patching.

>>nothing of value was provided.

>>>only political cover was sought.

I can imagine the conversation that led to this: "we're taking a shellacking in the court of public opinion for our All Writs Act exploit. Maybe we should offer up the most useless vulnerability we know of to show our disclosure "process" is real." Much LoL-Ing in the FBI conference room then ensued.
Score: 1 Votes (Like | Disagree)
doelcm82 Avatar
131 months ago
I heard this company can also hack into a 1996 Geo Tracker. But I'm not too worried about it.
Score: 1 Votes (Like | Disagree)

Popular Stories

Dynamic Island iPhone 18 Pro Feature

11 Reasons to Wait for the iPhone 18 Pro

Monday May 11, 2026 9:01 am PDT by
We're only four months out from the launch of Apple's premium next-generation smartphone lineup, and while we're not expecting a sea change in terms of functionality, there are still several enhancements rumored to be coming to the iPhone 18 Pro and iPhone 18 Pro Max. One thing worth noting is that Apple is reportedly planning a major change to its iPhone release cycle this year, adopting a...
iOS 26

iOS 26.5 Features: Everything New in iOS 26.5

Monday May 11, 2026 5:09 pm PDT by
Apple released iOS 26.5 after a few months of beta testing, and while it doesn't have the Siri features we were hoping for since those are being held until iOS 27, there are a handful of useful changes worth knowing about. Subscribe to the MacRumors YouTube channel for more videos. End-to-End Encryption for RCS Support for end-to-end encryption (E2EE) for RCS messages between iPhone and...
General Apps Reddit Feature

Reddit Starts Blocking Mobile Website, Pushing Users to App Instead

Monday May 11, 2026 6:10 am PDT by
Social network Reddit recently began blocking mobile visitors to its website while pushing them to download the official Reddit app, and it's fair to say that the move is not going down well with users. If you visit reddit.com on your iPhone today, you may see a new popup that can't be dismissed, asking you to "get the app to keep using Reddit." A Reddit spokesperson told Ars Technica...