Independent Security Researcher · Apple
2025 – PresentApple Security Bounty Program
- Reported a critical Account Takeover via the App Store with a working exploit & PoC; after Apple's same-day fix I found a unique bypass — earning a $15,000 bounty.
- Disclosed 2 unique CSRFs in the App Store and iTunes (Music) via the
itmss://scheme, affecting users' Apple Account billing information — $5,000 each. - Exploited an iTunes (Music) macOS flaw allowing any site to load into the internal webview and reach the JS bridge, exposing account data (dsId, email, guid, name, Machine ID).