Apple Launches Security Research Device Program to Give Bug Hunters Deeper OS Access to Find Vulnerabilities

Apple is today launching a new Apple Security Research Device Program that's designed to provide security researchers with special iPhones that are dedicated to security research with unique code execution and containment policies.

applesecuritydevice
Apple last year said it would be providing security researchers with access to "special" iPhones that would make it easier for them to find security vulnerabilities and weaknesses to make iOS devices more secure, which appears to be the program that's rolling out now.

The iPhones that Apple is providing to security researchers are less locked down than consumer devices and will make it easier to find serious security vulnerabilities.

Apple says the Security Research Device (SRD) offers shell access and can run any tools or entitlements, but other than that, it behaves similarly to a standard iPhone. SRDs are provided to security researchers on a 12-month renewable basis and remain Apple property. Bugs discovered with the SRD must be "promptly" reported to Apple or a relevant third-party.

If you use the SRD to find, test, validate, verify, or confirm a vulnerability, you must promptly report it to Apple and, if the bug is in third-party code, to the appropriate third party. If you didn't use the SRD for any aspect of your work with a vulnerability, Apple strongly encourages (and rewards, through the Apple Security Bounty) that you report the vulnerability, but you are not required to do so.

If you report a vulnerability affecting Apple products, Apple will provide you with a publication date (usually the date on which Apple releases the update to resolve the issue). Apple will work in good faith to resolve each vulnerability as soon as practical. Until the publication date, you cannot discuss the vulnerability with others.

Apple is accepting applications for the Security Research Device Program. Requirements include being in the Apple Developer Program, and having a track record finding security issues on Apple platforms.

Those that participate in the program will have access to extensive documentation and a dedicated forum with Apple engineers, with Apple telling TechCrunch that it wants the program to be a collaboration.

The Security Research Device Program will run alongside the bug bounty program, and hackers can file bug reports with Apple and receive payouts of up to $1 million, with bonuses possible for the worst vulnerabilities.

Top Rated Comments

Vanilla35 Avatar
31 months ago


Attachment Image
Score: 12 Votes (Like | Disagree)
alphaswift Avatar
31 months ago
Every government in the world just joined the Apple Developer Program.
Score: 7 Votes (Like | Disagree)
tehabe Avatar
31 months ago
The big issue is, that Apple controls everything in this programme. Apple could decide not to fix an issue and nobody would know because only Apple decides when to release the information. That is btw the reason why Google's Project Zero won't join this programme, it is against their 90 days publication policy.
Score: 3 Votes (Like | Disagree)
Sasparilla Avatar
31 months ago
Nice to see. Just keep making security better on it Apple.
Score: 2 Votes (Like | Disagree)
SecuritySteve Avatar
31 months ago

How is this different than the crash logs we already have in iOS?
There's a huge difference. Right now there's no way to inspect the file system to see if there was a successful breach, and crash logs only contain a stack trace and memory snapshot of application. With this kit you have full access to the device that normally would be protected. This lets you probe more sensitive areas such as Secure Enclave.

It also lets you do more detailed API testing and fuzzing as root on the iPhone, similar to what Google Project Zero's Ian Beer does.
Score: 2 Votes (Like | Disagree)
Saipher Avatar
31 months ago
This is great news!




Every government in the world just joined the Apple Developer Program.

Requirements include being in the Apple Developer Program, and having a track record finding security issues on Apple platforms.
I think we will be ok.
Score: 1 Votes (Like | Disagree)

Popular Stories

iphone 14 pro hands snowflakes 1

Best Black Friday iPhone Deals Still Available

Wednesday November 23, 2022 1:55 pm PST by
Cellular carriers have always offered big savings on the newest iPhone models during the holidays, and Black Friday 2022 is no different. Right now we're tracking notable offers on the iPhone 14 and iPhone 14 Pro devices from AT&T, Verizon, and T-Mobile. For even more savings, keep an eye on older models like the iPhone 13. Note: MacRumors is an affiliate partner with some of these vendors....
apple watch gold ornaments

Best Black Friday Apple Watch Deals Still Available

Wednesday November 23, 2022 9:31 am PST by
We're tracking all of the best Apple product discounts for Black Friday this week, and the Apple Watch always makes a great gift around the holiday season, so you're guaranteed to find solid discounts right now. In this article, you'll discover the best Black Friday sales on Apple Watch Series 8, Apple Watch SE, and Apple Watch Ultra. Note: MacRumors is an affiliate partner with some of these...
new airpods lineup black friday

Best Black Friday AirPods Deals Still Available

Tuesday November 22, 2022 10:01 am PST by
Although we've been tracking Black Friday deals for a few weeks now, the shopping holiday is officially kicking off this week and we're highlighting the best sales for each of Apple's product lines. In this article, you'll find the best Black Friday sales on AirPods 2, AirPods 3, AirPods Pro, AirPods Pro 2, and AirPods Max. Note: MacRumors is an affiliate partner with some of these vendors....
ipad holiday bulbs

Best Black Friday iPad Deals Still Available

Thursday November 24, 2022 12:25 pm PST by
Black Friday deals have been in full swing for the better part of a month, and now that the shopping holiday is officially here we're seeing even more solid discounts on Apple devices. We're highlighting the best sales for all of Apple's product lines, and in this article you'll find the best Black Friday sales on iPad, iPad Pro, iPad Air, and iPad mini. Note: MacRumors is an affiliate partner ...
mac imac snowflakes

Best Black Friday iMac and MacBook Deals Still Available

Thursday November 24, 2022 1:07 pm PST by
Our Black Friday coverage continues today with the best deals you can find on MacBook Pro, MacBook Air, and iMac. As with all Black Friday deals, we aren't sure how long any of these will last, and prices are always fluctuating, so if you see something you want, be sure to buy it soon. Note: MacRumors is an affiliate partner with some of these vendors. When you click a link and make a...
General Black Friday Deals 2022 Green

All the Apple Black Friday Deals You Can Still Get

Friday November 25, 2022 4:40 am PST by
Black Friday is winding down for 2022, but many Apple products are still seeing major discounts. In this article, you'll find every Apple device with a notable Black Friday sale. We'll be updating as prices change and new deals arrive, so be sure to keep an eye out if you don't see the sale you're looking for yet. Note: MacRumors is an affiliate partner with some of these vendors. When you...
General Black Friday Deals 2022 Blue

All the Apple Black Friday Deals You Can Get Right Now: AirPods, Apple TV, Mac, iPad, and More

Saturday November 19, 2022 8:00 am PST by
Last week was jam-packed with early Black Friday deals, and now that the shopping holiday is right around the corner, we're going back through all of the best sales you might have missed over the past week and updating as prices change and new deals arrive. As with all holiday shopping, there's no guarantee that better prices won't come around later in the season, but if you want to shop early,...
Best Buy November Deals Hero

Best Buy Reveals Black Friday Plans With Sitewide Sales Available Now

Tuesday November 22, 2022 3:49 pm PST by
Following in the footsteps of Target and Walmart, Best Buy this week detailed its plans for the Black Friday shopping holiday and its schedule looks a lot like other retailers. In terms of sales, Best Buy has the expected list of TVs, appliances, video games, computers, streaming devices, and more. Note: MacRumors is an affiliate partner with Best Buy. When you click a link and make a...