/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A Google bug report says the company fixed a Chrome zero-day that an Apple employee found during a March 2023 hacking competition but did not report to Google

Someone else in the competition, who did not find the bug and wasn't even on the same team, reported it. … Twitter: @iancoldwater : This seems so mundane that I'm not sure why it warranted a news story. Dude needed to get his disclosure signed off on by company higher-ups, and one of them was OOO. And? Slow news day? https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : Google spokesperson recommended we reach out to Apple “for any further details.” (We did but no response.) Love the low-key beef here. https://techcrunch.com/... @sherrod_im : We need a complete overhaul to bug bounties and bug reporting. This is crazy. Read the article before you @ Katie. https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : UPDATE: We have seen messages posted by the person (goes by Gallileo) who appears to be the one who originally found the bug. They said they did all they could to report the bug, but had to go through Apple's internal procedures first, hence the delay. https://techcrunch.com/... Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Google says an Apple employee found a Chrome zero-day during a hacking competition but did not report it. Someone else in the competition, who did not find the bug and wasn't even on the same team, reported it. https://techcrunch.com/... Forums: r/apple : Google says Apple employee found a zero-day but did not report it

TechCrunch Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

The episode lands in a long-running Apple-Google security relationship that has included public disagreement over how vulnerability findings are characterized, including Apple's criticism of Google Project Zero's framing of targeted attacks.

It also contrasts with Google's established practice of patching actively exploited Chrome flaws, as in its 2020 run of Chrome zero-day fixes. Here, the notable issue is not discovery alone but the handoff: a finder’s result reached Google only through an unrelated participant.

First-order effects

  • Google patched the reported Chrome zero-day after a participant outside the discovering team submitted it, reducing exposure for Chrome users once the fix was deployed.
  • The account puts Apple’s internal approval and disclosure path under scrutiny because its employee’s competition finding was not promptly conveyed to the affected vendor.

Second-order effects

  • Hacking competitions and participating employers may face pressure to make disclosure ownership, approval timelines, and vendor-notification responsibilities explicit before researchers compete.
  • For Google, the incident reinforces the value of accepting reports from any credible source rather than relying on the original finder or an employer to complete disclosure.

Third-order effects

  • If similar handoff failures recur, vulnerability discovery programs will be judged increasingly on time-to-vendor remediation rather than on the prestige of the researcher or event that produced a finding.
  • The case supports a broader shift toward accountable disclosure processes: cross-company security work needs clear escalation paths when legal or management review delays a report.

The trend: Security research is becoming as much a coordination and governance problem as a technical discovery problem, with remediation speed depending on reliable disclosure channels across organizational boundaries.

Discussion

  • @iancoldwater @iancoldwater on x
    This seems so mundane that I'm not sure why it warranted a news story. Dude needed to get his disclosure signed off on by company higher-ups, and one of them was OOO. And? Slow news day? https://techcrunch.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    Google spokesperson recommended we reach out to Apple “for any further details.” (We did but no response.) Love the low-key beef here. https://techcrunch.com/...
  • @sherrod_im @sherrod_im on x
    We need a complete overhaul to bug bounties and bug reporting. This is crazy. Read the article before you @ Katie. https://techcrunch.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    UPDATE: We have seen messages posted by the person (goes by Gallileo) who appears to be the one who originally found the bug. They said they did all they could to report the bug, but had to go through Apple's internal procedures first, hence the delay. https://techcrunch.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Google says an Apple employee found a Chrome zero-day during a hacking competition but did not report it. Someone else in the competition, who did not find the bug and wasn't even on the same team, reported it. https://techcrunch.com/...
  • r/apple r on reddit
    Google says Apple employee found a zero-day but did not report it