While trying to reset my mother's iPhone, I discovered what appears to be a way to bypass iCloud Activation Lock and reset the device without entering the linked Apple ID credentials. I tested the same process on another unused phone and got the same result. I haven't shared the method publicly. What is the proper way to report this security issue to Apple, and could it qualify for a bug bounty or other reward?
1 Answer
Report it directly through Apple’s official security vulnerability reporting process. Include the affected device and software versions, exact reproduction steps, expected versus actual behavior, and any limitations—but avoid posting the bypass publicly or using it on devices you don’t own. Apple may decide whether it qualifies for a security reward; payment isn’t guaranteed, and eligibility usually depends on the impact and whether the report meets their program requirements.

Thanks—I’ll document the steps carefully and submit them through Apple’s security reporting channel instead of sharing the method here.