Skip to main content

Apple paid a student $100,000 for successfully hacking a Mac

Hackers typically have a bad reputation, but without them, many security issues would remain undetected. This was proven by Ryan Pickren, a cybersecurity Ph.D. student at the Georgia Institute of Technology.

Pickren found a dangerous vulnerability on Apple Mac devices that granted unauthorized camera access. He reported it to Apple, and for his contribution, he was paid a record-setting $100,500 bounty.

College student Ryan Pickren received a hefty bounty form Apple for hacking a Mac webcam.
Image source: RyanPickren.com Image used with permission by copyright holder

The hacker described the hacking process in a lengthy blog post, going into detail as to how he was able to achieve the end result. The bugs revolve around exploiting issues with iCloud Sharing and the Safari 15 browser. Although the issue may seem situational and unlikely to be replicated, all it takes is one vulnerability for a hacker to gain control of a person’s device.

Recommended Videos

The vulnerability began with an iCloud sharing app called ShareBear. Through ShareBear, users are able to grant access to each other in order to seamlessly share documents. Once the user accepted an invitation to share a particular file with another person, Mac remembered this permission and never asked for it again. Unfortunately, while this seems like a nice quality-of-life feature at first glance, it can result in exploits.

Please enable Javascript to view this content

As the file is stored on the cloud and not locally, it can be swapped at any time after permission is granted. This can result in a simple image or text file being turned into an executable file with malicious code. Pickren used this exploit to change file types and gain full access to the user’s Mac.

ShareBear hacking flowchart.
Image source: RyanPickren.com Image used with permission by copyright holder

Pickren said on his website: “While this bug does require the victim to click ‘open’ on a popup from my website, it results in more than just multimedia permission hijacking. This time, the bug gives the attacker full access to every website ever visited by the victim. That means in addition to turning on your camera, my bug can also hack your iCloud, PayPal, Facebook, Gmail, etc. accounts, too.”

The file, once accessed via ShareBear, can be remotely launched at any moment without further prompt. As Pickren explains, this certainly opens the door to a potentially very dangerous hack, granting full access to the Mac in question.

Apple has fixed the bug in MacOS Monterey 12.0.1 (launched on October 25, 2021) after Pickren reported it in July. His $100,500 bounty is, according to Pickren, the highest Apple has ever offered through its security program. Apple has also recently fixed another critical bug, this time involving WebKit.

This wasn’t Pickren’s first Apple hacking rodeo. In 2019, he was able to hack into the iPhone camera and microphone, exposing a number of dangerous vulnerabilities in Apple’s code. Apple rewarded him generously for his efforts, giving him $75,000 in return for finding and reporting the bugs.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
How to tell if your webcam has been hacked
Razer webcam sitting on top of a monitor.

Having your webcam hacked is a terrifying prospect for many -- and a good reason to use a dedicated webcam cover. Not only does it represent an incredible invasion of privacy, but it has the potential to grab biometric data and other personal information that could be used to further expose you and steal your identity.

Often a hacked webcam is just part of a comprehensive malware assault, though, so protecting yourself against it involves having some of the best antivirus protection you can, while keeping your system updated. Even with robust protections in place, though, you should always keep an eye out for the tell-tale signs of a hacked webcam. Here's what to look out for.
The light on your webcam turns on at strange times

Read more
The biggest threat to the MacBook this year might come from Apple itself
The MacBook Air on a white table.

MacBooks have held a dominant position in the laptop world for the past few years. Though there have been meaningful rivals from the Windows side of the aisle, the MacBook Air and MacBook Pro still feel like they hold an unshakeable lead at the moment.

But according to the latest reports, the most serious challenger to the MacBook's reign won't come from Windows -- it'll come from within Apple in the form of some very advanced new iPads.
What's a computer?

Read more
Apple could fix the MacBook lineup with this one change
An open MacBook Pro on a table.

I was as surprised as anyone when Apple killed off the 13-inch MacBook Pro in October 2023, but at the time, it was definitely a pleasant revelation rather than a nasty shock. Now, though? There’s something I wish Apple had done differently.

Looking at Apple’s MacBook Pro lineup today, it’s almost perfect. How can Apple achieve that just-out-of-reach perfection? Maybe it should think about dropping the M3 MacBook Pro. I know, I know, it’s only just been released, but trust me -- it needs to go.
In an awkward spot

Read more