Apple Rewards Teen Who Discovered Group FaceTime Eavesdropping Bug

Apple promises a bug bounty payout and an educational gift to 14-year-old Grant Thompson for reporting a major Group FaceTime security flaw. The company also releases a comprehensive update to patch the vulnerability and block Live Photos on older devices.

Apple announces plans to compensate 14-year-old Grant Thompson for discovering a severe Group FaceTime bug that allows users to eavesdrop on others before they accept a call. The teenager and his mother initially struggle to report the flaw to Apple, but the issue eventually goes viral on social media before the company takes action.

The tech giant states that the payout falls under its official bug bounty program, which rewards researchers for privately disclosing security vulnerabilities. In addition to the standard financial reward, Apple offers an extra unspecified gift to support Thompson's education and officially credits the teen in its security advisory.

Alongside the compensation, Apple conducts a thorough security audit of the FaceTime service and releases iOS 12.1.4 to resolve the issue. This update patches the original eavesdropping flaw, fixes a newly discovered vulnerability in the Live Photos feature, and implements server-side blocks to protect users who have not yet upgraded their devices.

Read More at the original source →