A mother reported FaceTime bug to Apple over a week ago after her 14-year-old son discovered the flaw; Apple asked her to send report via developer account
SAN FRANCISCO — On Jan. 19, Grant Thompson, a 14-year-old in Arizona, made an unexpected discovery: Using FaceTime …
Context & Ripple Effects
The Group FaceTime eavesdropping bug was already public by the time this New York Times piece ran — what it adds is the timeline: Grant Thompson, a 14-year-old in Arizona, found the flaw on Jan. 19, and his mother's attempt to warn Apple stalled because the company directed her to file through a developer account rather than a consumer channel.
That detail reframes the week between discovery and disclosure as an Apple process failure, not just a code failure — and it set up the apology and promise of better bug-reporting practices that followed within days.
First-order effects
- Apple is forced to shut down Group FaceTime server-side and ship a fix under public pressure, while its consumer vulnerability intake — which bounced a concerned parent to a developer account — becomes the story itself.
Second-order effects
- Security researchers and journalists now have a template for scrutinizing not just Apple's bugs but its reporting pipeline, raising the cost of every future 'we knew and didn't act' narrative.
Third-order effects
- The pattern recurs: researchers who later flagged Screen Time failures — the 2023 confirmation that kids could bypass parental time limits and the 2024 X-rated-site bypass — describe the same slow, opaque intake, suggesting Apple's family-safety features carry a structural reporting gap that outlasts any single patch.
The trend: Consumer-facing security flaws at Apple keep surfacing through teenagers and parents first, exposing a vulnerability-disclosure process built for developers rather than families.