HT TECH wants to start sending you push notifications. Click allow to subscribe

BIGGEST Apple Bug Bounty reward of $100,500 paid to student over Mac webcam bug

Ryan Picker, a cyber security student, bagged the biggest Apple bug bounty reward ever paid for revealing Mac webcam bug that opened doors to hackers

By: HT TECH
Updated on: Aug 21 2022, 23:48 IST
Apple bug bounty reward of $100,500 was paid to a student who discovered Mac webcam bug that hackers culd exploit (methodshop/Pixabay)

Ryan Pickren, a cyber security student and former Amazon Web Services security engineer, has exposed a critical glitch in Apple devices and bagged a bug bounty of $100,500. The bounty is the highest ever Apple bug bounty reward paid to anyone. Pickren is no stranger to Apple vulnerabilities, as he discovered an iPhone and Mac camera vulnerability earlier in April 2020. Now, he has exposed another Mac webcam bug which allows hackers to breach into the device and access sensitive user information.

According to a report by AppleInsider, this Apple Mac webcam bug was related to a series of issues with iCloud and Safari browser. Hackers could potentially attack millions of Apple users through these bugs and gain unauthorized access to multiple user accounts information. Since then, Apple has fixed these issues.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
5% OFF
Apple iPhone 15 Plus 256GB
  • Black
  • 6 GB RAM
  • 256 GB Storage
₹94,900₹99,900
Buy now
9% OFF
Apple iPhone 15 256GB
  • Black
  • 6 GB RAM
  • 256 GB Storage
₹90,990₹99,900
Buy now
Apple MacBook Air MRE92HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 256 GB SSD
₹134,900
Buy now
Apple MacBook Air M2 MQKQ3HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 512 GB SSD
₹134,900
Buy now
Apple MacBook Pro MXK52HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 512 GB SSD
₹134,900
Buy now
Apple MacBook Pro M2 MNEH3HN A Ultrabook
  • Space Grey
  • 8 GB RAM
  • 256 GB SSD
₹100,000
Buy now
3% OFF
Apple iPad Pro 11 2022 WiFi 1TB
  • Silver
  • 16 GB RAM
  • 1 TB Storage
₹147,328₹151,900
Buy now
3% OFF
Apple iPad Pro 12 9 2022 WiFi plus Cellular 256GB
  • Silver
  • 8 GB RAM
  • 256 GB Storage
₹133,750₹137,900
Buy now
3% OFF
Apple iPad Pro 12 9 2022
  • Silver
  • 8 GB RAM
  • 128 GB Storage
₹124,051₹127,900
Buy now
10% OFF
Apple iPad 10 9 2022 WiFi plus Cellular 64GB
  • Blue
  • 64 GB Storage
₹53,900₹59,900
Buy now

How did these bugs expose Apple’s security

Pickren posted on his blog recently and gave a detailed explanation of how this vulnerability would allow hackers to gain access to user accounts details like Gmail, Facebook, Zoom and Paypal. Not only limited to this, the vulnerability opened access to all web-based accounts and information including iCloud and gave permission to use webcam and microphone to watch and listen to anything the user might be doing. This exposed a very critical security flaw in all Apple devices including Mac, iPhone and iPad. This is what ultimately led to him winning the huge Apple bug bounty reward.

Pickren explained that it all began with exploiting the Safari browser (Safari v15 when he attempted this) and gaining access to the webarchive files. Webarchives are local storage for Safari browser where it saves local copies of websites to open them faster.

"This is an awesome trick to let Safari rebuild the context of the saved website, but as the Metasploit authors pointed out back in 2013, if an attacker can somehow modify this file, they could effectively achieve UXSS [universal cross-site scripting] by design,” Pickren wrote in his post.

What it meant was that a user simultaneously downloads these webarchive in order to open an archived website. And this is where a malicious website could gain access. Pickren said that Apple did not consider this potential hacking scenario when first developing Safari’s webarchive functionality.

While Apple has not made a statement on these bugs, it has paid out the bounty to Pickren. Interestingly, the Apple bug bounty program has existed for a while now. Under the program, any hacker who can gain access to sensitive user information will be paid a sum of $100,000. Apple has surpassed that amount for the first time and paid Pickren a total reward of $100,500.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 26 Jan, 20:28 IST
Tags:

Sale

Mobiles Tablets Laptops
13% OFF
Apple iPhone 13 256GB
  • Blue
  • 4 GB RAM
  • 256 GB Storage
₹60,499₹69,900
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
5% OFF
Apple iPhone 15 Pro
  • Black Titanium
  • 8 GB RAM
  • 128 GB Storage
₹127,990₹134,900
Buy now
10% OFF
Apple iPhone 15 Plus 256GB
  • Black
  • 6 GB RAM
  • 256 GB Storage
₹80,590₹89,900
Buy now
2% OFF
Apple iPad Pro 12 9 2021 WiFi plus Cellular 512GB
  • Silver
  • 8 GB RAM
  • 512 GB Storage
₹139,900₹142,900
Buy now
17% OFF
Apple iPad Air 2020
  • Space Gray
  • 4 GB RAM
  • 64 GB Storage
₹49,999₹59,900
Buy now
2% OFF
Apple iPad Pro 11 WiFi Cellular 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹109,900₹111,900
Buy now
2% OFF
Apple iPad Pro 11 WiFi 512GB
  • Silver
  • 4 GB RAM
  • 512 GB Storage
₹109,900₹111,900
Buy now
38% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹32,790₹52,999
Buy now
27% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹21,990₹29,990
Buy now
29% OFF
Asus ROG Zephyrus G14 GA401QH BM072TS Laptop
  • Grey
  • 8 GB RAM
  • 512 GB SSD
₹65,990₹92,990
Buy now
35% OFF
Asus VivoBook Pro 15 M6500RC HN741WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹67,990₹104,990
Buy now
NEXT ARTICLE BEGINS