A Google bug report says the company fixed a Chrome zero-day that an Apple employee found during a March 2023 hacking competition but did not report to Google
Someone else in the competition, who did not find the bug and wasn't even on the same team, reported it. … Twitter: @iancoldwater : This seems so mundane that I'm not sure why it warranted a news story. Dude needed to get his disclosure signed off on by company higher-ups, and one of them was OOO. And? Slow news day? https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : Google spokesperson recommended we reach out to Apple “for any further details.” (We did but no response.) Love the low-key beef here. https://techcrunch.com/... @sherrod_im : We need a complete overhaul to bug bounties and bug reporting. This is crazy. Read the article before you @ Katie. https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : UPDATE: We have seen messages posted by the person (goes by Gallileo) who appears to be the one who originally found the bug. They said they did all they could to report the bug, but had to go through Apple's internal procedures first, hence the delay. https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Google says an Apple employee found a Chrome zero-day during a hacking competition but did not report it. Someone else in the competition, who did not find the bug and wasn't even on the same team, reported it. https://techcrunch.com/... Forums: r/apple : Google says Apple employee found a zero-day but did not report it
Context & Ripple Effects
The episode lands in a long-running Apple-Google security relationship that has included public disagreement over how vulnerability findings are characterized, including Apple's criticism of Google Project Zero's framing of targeted attacks.
It also contrasts with Google's established practice of patching actively exploited Chrome flaws, as in its 2020 run of Chrome zero-day fixes. Here, the notable issue is not discovery alone but the handoff: a finder’s result reached Google only through an unrelated participant.
First-order effects
- Google patched the reported Chrome zero-day after a participant outside the discovering team submitted it, reducing exposure for Chrome users once the fix was deployed.
- The account puts Apple’s internal approval and disclosure path under scrutiny because its employee’s competition finding was not promptly conveyed to the affected vendor.
Second-order effects
- Hacking competitions and participating employers may face pressure to make disclosure ownership, approval timelines, and vendor-notification responsibilities explicit before researchers compete.
- For Google, the incident reinforces the value of accepting reports from any credible source rather than relying on the original finder or an employer to complete disclosure.
Third-order effects
- If similar handoff failures recur, vulnerability discovery programs will be judged increasingly on time-to-vendor remediation rather than on the prestige of the researcher or event that produced a finding.
- The case supports a broader shift toward accountable disclosure processes: cross-company security work needs clear escalation paths when legal or management review delays a report.
The trend: Security research is becoming as much a coordination and governance problem as a technical discovery problem, with remediation speed depending on reliable disclosure channels across organizational boundaries.