Apple Rewards Teenager for Discovering FaceTime Eavesdropping Flaw
Apple awards a bug bounty to a 14-year-old who uncovers a major FaceTime audio eavesdropping glitch. Meanwhile, another researcher boycotts Apple over its lack of compensation for macOS vulnerabilities.
Apple provides a rare bug bounty to a 14-year-old Arizona teenager who discovers a severe security flaw in the FaceTime video-calling service. Grant Thompson uncovers a glitch that allows any iPhone user to call someone via Group FaceTime and secretly listen to the audio on the receiving end before the call is accepted, essentially turning the target device into a live microphone.
The technology giant acknowledges the teenager's discovery and issues a monetary reward alongside an additional gift that supports his education. Apple resolves the invasive eavesdropping issue with the release of the iOS 12.1.4 software update, which focuses heavily on patching bugs within the Group FaceTime feature after Thompson and his mother initially struggle to get a response from the company.
This payout sparks a broader conversation about Apple's bug bounty program, as a German security researcher named Linus Henze refuses to share details of a separate macOS vulnerability. Henze discovers a method to extract passwords, private keys, and tokens from a victim's keychain but withholds the information, stating he will not cooperate until Apple properly compensates security researchers for uncovering such critical weaknesses.