While trying to reset my mother's iPhone, I discovered a method that appeared to bypass iCloud Activation Lock and let the device be reset without the associated Apple ID credentials. I tested the same process on another phone linked to an iCloud account, and it worked there too. I haven't shared the method publicly. What is the proper way to report this potential security vulnerability to Apple, and could it qualify for a bug bounty or other reward?
1 Answer
Report it directly through Apple’s official security vulnerability reporting channel. Don’t publish the steps or share them with others, and preserve enough information for Apple to reproduce the issue safely, such as the device models, operating system versions, required conditions, and a clear description of what happens. Apple can determine whether it qualifies for a security reward, but payment isn’t guaranteed and depends on the impact, scope, and whether it’s a previously known issue.

Thanks—I’ll document the devices and versions and submit it privately instead of posting the bypass details.