Apple Invites Researchers to Apply for Special iPhone Designed for Finding Vulnerabilities

Apple today announced that it is accepting applications for its 2024 iPhone Security Research Device Program, allowing security researchers to get specialized Apple devices that make it easier to find critical iOS vulnerabilities.

apple security research program
The ‌iPhone‌ Security Research Device Program (SRDP) has been around since 2019, and researchers have used it to locate 130 high-impact security vulnerabilities. Apple says that researchers have helped it to implement "novel mitigations" for protecting iOS devices.

Over the course of the last six months, program participants have received 37 CVE credits for their findings, and have contributed to improvements for the XNU kernel, kernel extensions, and XPC services.

Researchers who participate in the SRDP are eligible for Apple Security Bounty payouts. Apple has rewarded more than 100 reports from SRDP researches, and says that "multiple awards" have reached $500,000 with a median award of close to $18,000.

The iPhone 14 Pro research devices that Apple provides to participants feature special hardware and software designed for security research. Researchers are able to configure or disable the iOS security protections to manipulate them in ways not possible with a standard ‌iPhone‌.

SRDs are available to security researchers who have a track record in security research both on the ‌iPhone‌ and other platforms, plus Apple is making devices available to university educators who want to use it as a teaching tool for computer science students.

Apple selects a limited number of participants each year to receive a research device, and applications are open until October 31, 2023. Selected participants will be notified in early 2024.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
Apple Watch Series 9

2024 Apple Watch Lineup: Key Changes We're Expecting

Tuesday July 16, 2024 7:59 am PDT by
Apple is seemingly planning a rework of the Apple Watch lineup for 2024, according to a range of reports from over the past year. Here's everything we know so far. Apple is expected to continue to offer three different Apple Watch models in five casing sizes, but the various display sizes will allegedly grow by up to 12% and the casings will get taller. Based on all of the latest rumors,...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...

Top Rated Comments

3530025 Avatar
12 months ago
Very nice! Hopefully this is going to make iOS even more secure!
Score: 10 Votes (Like | Disagree)
Spaceboi Scaphandre Avatar
12 months ago
Mmm I love a good terminal.

Wish I could get my hands on this iPhone. The fun things I could do with an iPhone that had root access just has me salivating.

Alas, I'll just have to wait until Apple's forced to enable sideloading next year.
Score: 10 Votes (Like | Disagree)
3530025 Avatar
12 months ago

Alas, I'll just have to wait until Apple's forced to enable sideloading next year.
This! Sideloading will get iPhone to another level.

And the best thing is - it is optional. You don't have to sideload anything if you don't want to!
Score: 10 Votes (Like | Disagree)
MrENGLISH Avatar
12 months ago

I can only show you the door. You're the one who has to walk through it.
Score: 9 Votes (Like | Disagree)
now i see it Avatar
12 months ago
and of course, one of these phones doesn’t end up in the hands of a nation-state hacker. Of course not.
Score: 8 Votes (Like | Disagree)
3530025 Avatar
12 months ago

You say you don’t understand the argument. And you don’t understand the difference.

I’m going to try to explain…

Tech enthusiasts can already get pretty much whatever they need onto their iPhones.

But tech novices (a HUUUUGE portion of iOS users) cannot.

After sideloading is built-in it becomes MUCH easier to do it. For everybody.

A few years after sideloading everybody is going to have a way to save 30% if you follow the three steps on their site to sideload their app instead of getting it through the AppStore. Netlix/Disney+, Epic Games, whatever the latest fad AI app or messaging plugin or whatever, they’ll all have a strong incentive for themselves and their customers to do it.

And plenty will sideload. It will become part of using an iPhone.

This isn’t a HUGE problem for those trusted developers. But it’s the normalized behaviour that opens the door for tons more malware installs.

Grandpa Jim has sideloaded his MLB app before to save $30, I guess he has to do it again to get the MLB playoffs update. Only it’s malware disguised as from MLB.

These tech novices don’t install apps on their macs (if they even have PCs), they certainly don’t install Mac apps from outside the AppStore.

A HUGE portion of the iPhone user base (at least 90%) are nowhere near as tech savvy as you or me, and probably at least half of them are Grampa Jims.

TL;DR: Having effectively no way for Grampa Jim to get himself in trouble with malware means the iPhone is safe for that hundred million people who know nothing about tech. Opening up sideloading for us nerds (who don’t actually NEED it to sideload), means you make the iPhone MASSIVELY less safe for the 100M Grampa Jims.
Well your whole post is not based on facts but on massive assumptions.


* You automatically assume it will be much easier to sideload. Yet you don't have any factual data to this. It may be behind multiple warnings and settings and you may require to do some stuff (i.e. allow it manually via computer) in order to allow this. There's no exact specification out yet, so we don't know how exactly will sideload work.
* You assume plenty will sideload. This just does not have any factual basis. Many Apple users trust the ecosystem and Apple claims about security of App Store. We really don't know how widespread will sideload be. It may be minority thing.
* You assume grandpa Jim sideload just to save $30. Where would grandpa Jim get this app? Is he browsing torrents or warez sites? Really? Does he really want to go beyond Apple ecosystem and convenience just to save $30 when he bought 1000 USD phone already?
* You assume there will be no security measure in place when installing potential malware to your device. There easily may be.
* You forget about sandbox. iPhone has sandbox built in. No app is able to access other app's data or features that you did not allow permissions to.


So I disagree with you, because it's just your assumptions and your opinions without any factual base at this point. You may be right, but you may be totally wrong too.
Score: 6 Votes (Like | Disagree)