Apple Invites Researchers to Apply for Special iPhone Designed for Finding Vulnerabilities

Apple today announced that it is accepting applications for its 2024 iPhone Security Research Device Program, allowing security researchers to get specialized Apple devices that make it easier to find critical iOS vulnerabilities.

apple security research program
The ‌iPhone‌ Security Research Device Program (SRDP) has been around since 2019, and researchers have used it to locate 130 high-impact security vulnerabilities. Apple says that researchers have helped it to implement "novel mitigations" for protecting iOS devices.

Over the course of the last six months, program participants have received 37 CVE credits for their findings, and have contributed to improvements for the XNU kernel, kernel extensions, and XPC services.

Researchers who participate in the SRDP are eligible for Apple Security Bounty payouts. Apple has rewarded more than 100 reports from SRDP researches, and says that "multiple awards" have reached $500,000 with a median award of close to $18,000.

The iPhone 14 Pro research devices that Apple provides to participants feature special hardware and software designed for security research. Researchers are able to configure or disable the iOS security protections to manipulate them in ways not possible with a standard ‌iPhone‌.

SRDs are available to security researchers who have a track record in security research both on the ‌iPhone‌ and other platforms, plus Apple is making devices available to university educators who want to use it as a teaching tool for computer science students.

Apple selects a limited number of participants each year to receive a research device, and applications are open until October 31, 2023. Selected participants will be notified in early 2024.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Production Will Reportedly Begin Ramping Up in October

Tuesday July 23, 2024 2:00 pm PDT by
Following nearly two years of rumors about a fourth-generation iPhone SE, The Information today reported that Apple suppliers are finally planning to begin ramping up mass production of the device in October of this year. If accurate, that timeframe would mean that the next iPhone SE would not be announced alongside the iPhone 16 series in September, as expected. Instead, the report...
iPhone 17 Plus Feature

iPhone 17 Lineup Specs Detail Display Upgrade and New High-End Model

Monday July 22, 2024 4:33 am PDT by
Key details about the overall specifications of the iPhone 17 lineup have been shared by the leaker known as "Ice Universe," clarifying several important aspects of next year's devices. Reports in recent months have converged in agreement that Apple will discontinue the "Plus" iPhone model in 2025 while introducing an all-new iPhone 17 "Slim" model as an even more high-end option sitting...
Generic iPhone 17 Feature With Full Width Dynamic Island

Kuo: Ultra-Thin iPhone 17 to Feature A19 Chip, Single Rear Camera, Semi-Titanium Frame, and More

Wednesday July 24, 2024 9:06 am PDT by
Apple supply chain analyst Ming-Chi Kuo today shared alleged specifications for a new ultra-thin iPhone 17 model rumored to launch next year. Kuo expects the device to be equipped with a 6.6-inch display with a current-size Dynamic Island, a standard A19 chip rather than an A19 Pro chip, a single rear camera, and an Apple-designed 5G chip. He also expects the device to have a...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Less Than Two Months Away: Everything We Know

Thursday July 25, 2024 5:43 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
icloud private relay outage

iCloud Private Relay Experiencing Outage

Thursday July 25, 2024 3:18 pm PDT by
Apple’s iCloud Private Relay service is down for some users, according to Apple’s System Status page. Apple says that the iCloud Private Relay service may be slow or unavailable. The outage started at 2:34 p.m. Eastern Time, but it does not appear to be affecting all iCloud users. Some impacted users are unable to browse the web without turning iCloud Private Relay off, while others are...
iPhone 17 Plus Feature Purple

iPhone 17 Rumored to Feature Mechanical Aperture

Tuesday July 23, 2024 9:32 am PDT by
Apple is planning to release at least one iPhone 17 model next year with mechanical aperture, according to a report published today by The Information. The mechanical system would allow users to adjust the size of the iPhone 17's aperture, which refers to the opening of the camera lens through which light enters. All existing iPhone camera lenses have fixed apertures, but some Android...

Top Rated Comments

3530025 Avatar
12 months ago
Very nice! Hopefully this is going to make iOS even more secure!
Score: 10 Votes (Like | Disagree)
Spaceboi Scaphandre Avatar
12 months ago
Mmm I love a good terminal.

Wish I could get my hands on this iPhone. The fun things I could do with an iPhone that had root access just has me salivating.

Alas, I'll just have to wait until Apple's forced to enable sideloading next year.
Score: 10 Votes (Like | Disagree)
3530025 Avatar
12 months ago

Alas, I'll just have to wait until Apple's forced to enable sideloading next year.
This! Sideloading will get iPhone to another level.

And the best thing is - it is optional. You don't have to sideload anything if you don't want to!
Score: 10 Votes (Like | Disagree)
MrENGLISH Avatar
12 months ago

I can only show you the door. You're the one who has to walk through it.
Score: 9 Votes (Like | Disagree)
now i see it Avatar
12 months ago
and of course, one of these phones doesn’t end up in the hands of a nation-state hacker. Of course not.
Score: 8 Votes (Like | Disagree)
3530025 Avatar
12 months ago

You say you don’t understand the argument. And you don’t understand the difference.

I’m going to try to explain…

Tech enthusiasts can already get pretty much whatever they need onto their iPhones.

But tech novices (a HUUUUGE portion of iOS users) cannot.

After sideloading is built-in it becomes MUCH easier to do it. For everybody.

A few years after sideloading everybody is going to have a way to save 30% if you follow the three steps on their site to sideload their app instead of getting it through the AppStore. Netlix/Disney+, Epic Games, whatever the latest fad AI app or messaging plugin or whatever, they’ll all have a strong incentive for themselves and their customers to do it.

And plenty will sideload. It will become part of using an iPhone.

This isn’t a HUGE problem for those trusted developers. But it’s the normalized behaviour that opens the door for tons more malware installs.

Grandpa Jim has sideloaded his MLB app before to save $30, I guess he has to do it again to get the MLB playoffs update. Only it’s malware disguised as from MLB.

These tech novices don’t install apps on their macs (if they even have PCs), they certainly don’t install Mac apps from outside the AppStore.

A HUGE portion of the iPhone user base (at least 90%) are nowhere near as tech savvy as you or me, and probably at least half of them are Grampa Jims.

TL;DR: Having effectively no way for Grampa Jim to get himself in trouble with malware means the iPhone is safe for that hundred million people who know nothing about tech. Opening up sideloading for us nerds (who don’t actually NEED it to sideload), means you make the iPhone MASSIVELY less safe for the 100M Grampa Jims.
Well your whole post is not based on facts but on massive assumptions.


* You automatically assume it will be much easier to sideload. Yet you don't have any factual data to this. It may be behind multiple warnings and settings and you may require to do some stuff (i.e. allow it manually via computer) in order to allow this. There's no exact specification out yet, so we don't know how exactly will sideload work.
* You assume plenty will sideload. This just does not have any factual basis. Many Apple users trust the ecosystem and Apple claims about security of App Store. We really don't know how widespread will sideload be. It may be minority thing.
* You assume grandpa Jim sideload just to save $30. Where would grandpa Jim get this app? Is he browsing torrents or warez sites? Really? Does he really want to go beyond Apple ecosystem and convenience just to save $30 when he bought 1000 USD phone already?
* You assume there will be no security measure in place when installing potential malware to your device. There easily may be.
* You forget about sandbox. iPhone has sandbox built in. No app is able to access other app's data or features that you did not allow permissions to.


So I disagree with you, because it's just your assumptions and your opinions without any factual base at this point. You may be right, but you may be totally wrong too.
Score: 6 Votes (Like | Disagree)