Bug bounty hunters are people who know the details of cybersecurity and how software works. With their knowledge, they work by finding flaws and vulnerabilities on their targets, for a price.
Big platforms often rely on third-party 'white hat hackers' and bug bounty hunters to find bugs. And Apple is no exception.
Apple has long provided a way for bounty hunters to report. With the program, Apple allows them to detect the bugs and report them before the public hears about them, in order to prevent incidents of widespread abuse.
But it is only starting this time that the company starts sending those bounty hunters "rooted" iPhones.
This way, the bounty hunters can get deeper access to the core iOS to find any security vulnerability present in the operating system.
As part of Apple Security Research Device Program, announced earlier this July 2020, Apple refers to these “rooted” iPhones as Security Research Device (SRD). Researchers who had applied for this program earlier are said to have just received their SRDs.

The rooted iPhone offers shell access, meaning that researchers will not need to jailbreak the phones to do research.
This enables them to gain access to the kernel and other low-level areas of the iOS operating system in order to investigate the platform for security issues, by running whatever tools they want without being held to the usual arbitrary code execution limits of iOS.
The iPhones are also specially-configured, and are equipped with unique code execution and containment policies to support security research.
In other words, this allows third-party researchers to access the same kind of hardware that Apple’s internal security teams examine. The ability to try and attack lower-security devices can help find exploits and vulnerabilities that would otherwise be obfuscated or difficult to track down.
What's more, program participants also have access to extensive documentation and a dedicated forum with Apple engineers for collaborative purposes.
Apart from this, “the SRD behaves as closely to a standard iPhone as possible in order to be a representative research target,” explained Apple.
The only reason Apple provides these rooted phones, is to help researchers find bugs in order for the company to continuously improve the security of iOS-powered devices. Apple believes that the contributions of security researchers will assist the company in achieving its goal of increasing safety for consumers.
Because of this, there are limitations the researchers have while holding this phone.
Read: Bug Bounty Hunters, And How Their Love For Bugs Is Saving The Web
First, Apple states that the SRDs are provided on a 12-month renewable basis and shall remain the property of Apple.
“They are not meant for personal use or daily carry, and must remain on the premises of program participants at all times. Access to and use of SRDs must be limited to people authorized by Apple,” said Apple.
Second, for developers to be a part of this program they need to be a membership Account Holder in the Apple Developer Program. Also, they are required to have a proven track record of success in finding security issues on Apple platforms, or other operating systems.
Third, Apple suggests that there is a limited quantity of these devices available, so not everyone who applies can get one. But applications should automatically roll over for possible eligibility in 2021.
Because the main purpose of this program is to find bugs, Apple is rewarding the researchers if they can find any vulnerability present in the operating system.
Any issue that is found using an SRD is automatically considered for reward through the Apple Security Bounty.
Apple's Security Research Device Program runs alongside the bug bounty program, meaning that submissions of security issues will be eligible for the usual bounty rewards, as appropriate. Here, researchers who locate vulnerabilities can receive payouts of up to $1.5 million.
Apple said that it values collaborating with independent researchers and appreciates the work they do on Apple platforms.




















































































































































































































































































































































































