
A security researcher in Germany, who last month discovered a macOS that allowed him to access passwords and user information stored in Keychain, has now said he has reconsidered his decision not to share that information with Apple, according to 9to5Mac.
Linus Henze shared his findings in a YouTube video, which he posted on February 3. But at that time he had stated that he does not plan to share the security vulnerability with Apple, arguing that his decision was due to the fact that while the tech giant offers a bounty program for discovering bugs for iOS, it does not offer something similar for macOS. Henze wrote that he hopes that «this will force Apple to open a bounty program for bugs sometime».
Henze claims that Apple contacted him about the security vulnerability on February 5. He then offered to share information about the vulnerability and provide a patch, if the company would issue an official statement regarding why it does not have a bug bounty program for macOS. He claims that after receiving no response from the company, he tried again to get in touch with Apple's security team with the same offer.
On Thursday, however, Henze posted a tweet that he shared the information with Apple, because, as he said, security is very important to him.
The Apple bug bounty program for iOS has been around for a few years, but it is still not perfect. And those security researchers who discover bugs know that they can earn much more than if they report them directly to the company, as Motherboard reported in 2017. Nikias Bassen of Zimperium said on the website at that time that researchers could “receive more cash if they sold the bugs they discovered to others”.
