Researcher, analyst, enthusiast; I’ve been called all these and more. I’ve broken stories at MacRumors, uncovered unreleased Apple products, and love finding out what features companies are working on next in their apps.
Impact: Processing a maliciously crafted text message may lead to application denial of service.
Fixed in: iOS 13.5, tvOS 13.4.5, watchOS 6.2.5
Impact: Multiple Apple contractor credentials were publicly exposed online, potentially granting unauthorized access to confidential information. Furthermore, confidential documents were discovered stored with inadequate security measures.
Fixed in: July 2025 – Apple Bug Bounty Received
Impact: Two Apple contractor credentials were publicly exposed online, potentially granting access to confidential information.
Fixed in: September 2024 – Apple Bug Bounty Received
Impact: Visiting the affected site temporarily exposed confidential dashboard content before redirecting to the authentication page.
Fixed in: December 2024