Questions about the Apple Security Bounty

from blog The Desolation of Blog, | ↗ original
I'm not a professional security researcher, I'm just an app developer. I don't know how security bounty programs work, as I've never participated in one until now. On August 8 at the Black Hat 2019 conference, Apple announced an expansion of their bounty program for security vulnerabilities. The previous, limited bounty program was by invitation only, and it covered iOS only, whereas the expanded bounty program would be open to anyone and cover all of Apple's operating systems, including macOS. I have over a decade of experience in Mac development, and I've discovered several security issues in macOS during that time, so Apple's announcement of a bounty program inspired me to look for more. Within a couple of months — before the release of macOS 10.15 Catalina on October 7 — I found a couple of issues to report.