Skip to main content

Researcher who found macOS Keychain security hole is sharing details with Apple, even though company yet to promise macOS bug bounty program

Last month, we covered a macOS Keychain exploit that seemingly could expose user credentials and passwords. At the time, the researcher Linus Henze did not disclose the workings of the exploit to Apple as a protest because Apple does not offer a bug bounty reward scheme for macOS. Despite no change on that front from Apple, Henze has now decided to share his findings with the company to protect users.

The iOS bug bounty program launched in 2017. The lack of bug bounties for macOS exploits is seen as a slight against Mac users, as if Apple does not value their security as much as iOS customers. Many believe that Apple will eventually set up a macOS bug bounty program, it’s just dragging its feet.

Henze is obviously upset that his work will seemingly go unpaid, unless Apple changes its mind soon. Around the time that we originally covered the bug, Henze says that he received communication from Apple asking him to send them the details of the exploit. He said he would if he could get a commensurate payout for his findings. Apple did not respond. On February 8th, Henze sent Apple Security an email asking for an official statement as to why Apple is not offering a bug bounty program for Mac users.

This email was also apparently ignored. It’s disappointing that Apple would not at least acknowledge that a macOS bug bounty program is in the works. With his stunts falling on seemingly deaf ears, he has now submitted an explanation of his exploit to Apple as he believes a critical patch is necessary to protect Mac users.

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Benjamin Mayo Benjamin Mayo

Benjamin develops iOS apps professionally and covers Apple news and rumors for 9to5Mac. Listen to Benjamin, every week, on the Happy Hour podcast. Check out his personal blog. Message Benjamin over email or Twitter.