A security researcher who has shared iOS flaws before demos a macOS Keychain exploit, won't share details with Apple because of the lack of a macOS bug bounty
Benjamin Mayo / 9to5Mac :
Context & Ripple Effects
This is the second time a macOS Keychain exposure has been demonstrated publicly: in 2017 an ex-NSA researcher at Synack showed a zero-day that let apps exfiltrate Keychain contents in High Sierra. The difference now is disclosure posture — the researcher has shared iOS flaws before but is withholding this exploit's details because macOS sits outside Apple's bounty scope.
That posture is consistent with the program's documented history: interviews in mid-2017 found a slow start for Apple's bug bounty, with researchers citing rewards too small to justify forgoing publication, and by 2021 researchers were telling the Washington Post that confusion over payments and long fix delays undermined the program. The one counterexample on record is Apple's own doing — a $100K payout for a Sign in with Apple flaw shows the company pays when a flaw falls inside the program's boundaries.
First-order effects
- Apple receives no private report for this Keychain exploit, so its engineers learn of the flaw only from the public demo and must reverse-engineer it without the researcher's technical details.
- Security researchers weighing whether to report macOS flaws see confirmation that outside iOS's scope there is no financial path, pushing disclosure toward public demonstration.
Second-order effects
- Third-party Mac security vendors gain a marketing window: an undetailed public Keychain exploit lets them sell detection and hardening while Apple works from partial information.
- Enterprise Mac buyers face a credential-store risk they cannot patch on the researcher's timeline, strengthening the case for third-party endpoint tools alongside Apple's own fixes.
Third-order effects
- If Apple keeps macOS outside bounty scope while paying six figures for in-scope web-service flaws like Sign in with Apple, vulnerability research structurally migrates toward whatever platform pays, leaving the desktop OS covered mainly by public demos.
- A pattern of withheld details forces Apple toward either expanding the bounty or accepting slower, less-informed patches — a governance choice about how closed companies buy security research at all.
The trend: Apple's bug bounty is becoming a two-tier market where in-scope flaws get paid reports and out-of-scope platforms like macOS get public demonstrations instead.