vulns.co
/
GKData.io MCP

BRClient and browser security · 1 min read

iCloud sharing consent and Safari trust boundaries failed together

The cited researcher documents a USD 100,500 award for this reported chain.

Read the primary source BRClient and browser securityReviewed 2026-10-02

Root cause

Consent to open shared content remained effective after material content changes, and cross-application trust handling failed to preserve browser isolation. Review whether persisted consent remains valid as shared resources evolve.

Demonstrated impact

The researcher reports access across website security contexts and media permissions; additional research covered local-file exposure.

Lessons for review

  • Use one coherent origin model for permission enforcement.
  • Invalidate persistent consent when the underlying resource or trust context materially changes.

Award and evidence

USD 100,500Bug Bounty · Researcher Reported

One award for the reported vulnerability chain, not this amount per CVE.

Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.

  • One award for a reported chain; not a separate award per CVE
  • Broader research included four bugs, only two used for the camera demonstration
  • Complete remediation and payment dates are not stated; page says all issues patched by early 2022
  • Publication date is unknown in the primary source, so recency is explicitly uncertain.

Recorded timeline

Reported
2021-07explicit

Sources and provenance

  1. iCloud sharing consent and Safari trust boundaries failed together Ryan Pickren · reviewed 2026-10-02
  2. Apple security release advisory Apple · reviewed 2026-10-02
  3. Apple security release advisory Apple · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software