Apple Paid Hacker $75,000 for Uncovering Zero-Day Camera Exploits in Safari

Apple paid out $75,000 to a hacker for identifying multiple zero-day vulnerabilities in its software, some of which could be used to hijack the camera on a MacBook or an iPhone, according to Forbes.

ipadprocamerabumps
A zero-day vulnerability refers to a security hole in software that is unknown to the software developer and the public, although it may already be known by attackers who are quietly exploiting it.

Security researcher Ryan Pickren reportedly discovered the vulnerabilities in Safari after he decided to "hammer the browser with obscure corner cases" until it started showing weird behavior.

The bug hunter found seven exploits in all. The vulnerabilities involved the way that Safari parsed Uniform Resource Identifiers, managed web origins and initialized secure contexts, and three of them allowed him to get access to the camera by tricking the user to visit a malicious website.

"A bug like this shows why users should never feel totally confident that their camera is secure," Pickren said, "regardless of operating system or manufacturer."

Pickren reported his research through Apple's Bug Bounty Program in December 2019. Apple validated all seven bugs immediately and shipped a fix for the camera kill chain a few weeks later. The camera exploit was patched in Safari 13.0.5, released January 28. The remaining zero-day vulnerabilities, which Apple judged to be less severe, were patched in Safari 13.1, released on March 24.

Apple opened its bug bounty program to all security researchers in December 2019. Prior to that, Apple's bug bounty program was invitation-based and non-iOS devices were not included. Apple also increased the maximum size of the bounty from $200,000 per exploit to $1 million depending on the nature of the security flaw.

When submitting reports, researchers must include a detailed description of the issue, an explanation of the state of the system when the exploit works, and enough information for Apple to reliably reproduce the issue.

This year, Apple plans to provide vetted and trusted security researchers and hackers with "dev" iPhones, or special iPhones that provide deeper access to the underlying software and operating system that will make it easier for vulnerabilities to be discovered.

These iPhones are being provided as part of Apple's forthcoming iOS Security Research Device Program, which aims to encourage additional security researchers to disclose vulnerabilities, ultimately leading to more secure devices for consumers.

Top Rated Comments

Skeith Avatar
31 months ago
Good Apple.
Score: 10 Votes (Like | Disagree)
Justanotherfanboy Avatar
31 months ago

The iPhone needs a camera light hardwired to the camera itself just like the Mac so that exploits like this would at least be noticeable.

So only $75,000 for an exploit that can allow remotely accessing the camera on the Mac or iPhone? Then what in the hell is a $1,000,000 bounty for?
Remote root access, allowing an attacker complete takeover of the system, including deleting the admin account, changing password, etc.
Score: 9 Votes (Like | Disagree)
The Oak Avatar
31 months ago
Considering the median US income is around $60k ... $75k is more than a year's work for most Americans. I definitely would not complain.
Score: 7 Votes (Like | Disagree)
tridley68 Avatar
31 months ago
$75000 sounds a little light he should have held out for more.
Score: 6 Votes (Like | Disagree)
MacBH928 Avatar
31 months ago
cameras and microphones should have physical disconnection
Score: 5 Votes (Like | Disagree)
JosephAW Avatar
31 months ago
I was just saying this about bandaids and electrical tape on cameras in the other forum post about the mic.

If you can't update your safari because Apple EOL and obsoleted your devices then this is the only work around.
Score: 4 Votes (Like | Disagree)

Popular Stories

iPhone 14 Pro Lineup Feature Purple

Apple Planning to Hold iPhone 14 Event on September 7

Wednesday August 17, 2022 9:51 am PDT by
Apple is aiming to hold its first fall event on Wednesday, September 7, reports Bloomberg's Mark Gurman. The event will focus on the iPhone 14 models and the Apple Watch Series 8. The standard iPhone 14 models are expected to get few changes, but the iPhone 14 Pro models will include updated camera technology, the removal of the notch in favor of a pill-shaped and hole-punch cutout, an A16...
iOS 15

Apple Releases iOS 15.6.1 and iPadOS 15.6.1 With Bug Fixes

Wednesday August 17, 2022 9:50 am PDT by
Apple today released iOS and iPadOS 15.6.1, minor updates to the iOS and iPadOS 15 operating systems initially released in September 2021. iOS 15.6.1 and iPadOS 15.6.1 come a month after Apple released iOS 15.6 and iPadOS 15.6 with new Live Sports features and bug fixes. The iOS 15.6.1 and iPadOS 15.6.1 updates can be downloaded for free and the software is available on all eligible devices...
tiktok logo

TikTok's In-App Browser Reportedly Capable of Monitoring Anything You Type

Thursday August 18, 2022 4:25 pm PDT by
TikTok's custom in-app browser on iOS reportedly injects JavaScript code into external websites that allows TikTok to monitor "all keyboard inputs and taps" while a user is interacting with a given website, according to security researcher Felix Krause, but TikTok has reportedly denied that the code is used for malicious reasons. Krause said TikTok's in-app browser "subscribes" to all...
airpods pro black background

AirPods Pro 2: Five New Features and Improvements to Expect

Sunday August 14, 2022 3:28 pm PDT by
Apple's second-generation AirPods Pro are finally nearing launch, with a release expected later this year. If you are considering upgrading to the new AirPods Pro once they are released, keep reading for a list of five new features to expect. In addition to all-new features, the second-generation AirPods Pro will likely adopt some features added to the standard AirPods last year. H2 Chip ...
ipados 16 stage manager

Apple Criticized for 'Fundamentally Misguided' Approach to Stage Manager in iPadOS 16

Friday August 19, 2022 1:57 am PDT by
Stage Manager in the iPadOS 16 beta is receiving heavy criticism for being "fundamentally misguided" in its approach to bringing a new level of multitasking to the iPad experience, with some even calling on Apple to delay the feature entirely due to its shortcomings. Federico Viticci, the founder and editor in chief of MacStories and a prominent member of the Apple community, outlined his...
M2 Pro and Max Feature

3nm M2 Pro Chip for MacBook Pro Reportedly Entering Production Later This Year

Thursday August 18, 2022 7:39 am PDT by
TSMC will begin production of 3nm chips for Apple by the end of 2022, according to a report this week from Taiwan's Commercial Times. A separate report from the publication claimed that TSMC will begin mass production of 3nm chips in September. The report, citing industry insiders, claims that the M2 Pro chip may be the first to use TSMC's advanced 3nm process. Bloomberg's Mark Gurman...