Google Claims Apple Employee Found A Security Vulnerability But Did Not Report It – News18

Last Updated: July 21, 2023, 17:05 IST

Apple and Google continue to compete

Apple and Google continue to compete

The security issue was found by one person but reported by another who was rewarded by Google for his effort.

Google is unlikely to be pleased with one of Apple’s employees who found a zero-day vulnerability but did not report the issue so that the company could work on a fix for it. The vulnerability found by the employee doesn’t carry a huge security threat but Google is not pleased with how it got to know about the issue.

As per the official comment in the bug report, Google didn’t know that it was unaware of a zero-day security issue, which did not have a fix, putting millions of users at risk.

Now the interesting thing is how Google found out about the problem and who reported the issue. The company claims an unnamed person reported the issue, which was originally discovered by the Apple employee who was part of the Capture The Flag hacking event in March this year.

“This issue was reported by sisu from CTF team HXP and discovered by a member of Apple Security Engineering and Architecture (SEAR) during HXP CTF 2022,” as mentioned by the Google employee. Incidents like these are not uncommon but what is really intriguing is that the Apple employee decided against reporting the issue.

Reports suggest the person was caught up with other work and since the issue was not really threatening, he decided to wait it out and eventually report to Google, by which time, the company had already got the bug report from another person. As per the bug report data, the issue was fixed on March 29 and Google awarded $10,000 (Rs 8 lakh approx) to the person who actually shared the bug, not the Apple employee who found it in the first place.

Zero-day threats have become a common sight, which is a worrying sign for the likes of Apple, Google and Microsoft among others. These vulnerabilities need constant support from the hacker groups, so that a fix can be issued to the consumers before causing any major impact in the market.

For all the latest Technology News Click Here 

Read original article here

Denial of responsibility! TechAI is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.