Security News > 2023 > August > Apple offers security researchers specialized iPhones to tinker with
Apple is inviting security researchers to apply for the Apple Security Research Device Program again, to discover vulnerabilities and earn bug bounties.
In the intervening years, participating researchers have identified 130 security-critical vulnerabilities and have indirectly helped Apple implement security improvements in the XNU kernel, kernel extensions, and XPC services around the system.
The Security Research Device is a specially-built hardware variant of iPhone 14 Pro, with tooling and options that allow researchers to configure or disable many advanced security protections of iOS. Researchers can install and boot custom kernel caches on it, run arbitrary code, start services at startup, persist content across restarts, and more.
"To help ensure that user devices aren't affected by the security research device execution policy, the policy changes are implemented in a variant of iBoot and in the Boot Kernel Collection."
Reported security issues will be eligible for awards under the Apple Security Bounty.
"Each year, we select a limited number of security researchers to receive an SRD through an application process that's primarily based on a track record in security research, including on platforms other than iPhone," the Apple Security Engineering and Architecture team explained.
News URL
https://www.helpnetsecurity.com/2023/08/31/iphone-security-research/
Related news
- MUT-1244 targeting security researchers, red teamers, and threat actors (source)
- Researchers Uncover Major Security Flaw in Illumina iSeq 100 DNA Sequencers (source)
- Apple Patches Actively Exploited Zero-Day Affecting iPhones, Macs, and More (source)
- Apple plugs security hole in its iThings that's already been exploited in iOS (source)
- Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085) (source)
- SLAP, Apple, and FLOP: Safari, Chrome at risk of data theft on iPhone, Mac, iPad Silicon (source)
- Week in review: Apple 0-day used to target iPhones, DeepSeek’s popularity exploited by scammers (source)