Root cause
URL parsing, origin identity, and secure-context decisions were inconsistent with the identity used for stored permissions. Defensive design should use one coherent origin model across permission enforcement.
Demonstrated impact
Unauthorized camera and microphone access under previously granted website permissions.
Lessons for review
- Use one coherent origin model for permission enforcement.
- Invalidate persistent consent when the underlying resource or trust context materially changes.
Award and evidence
One award for the reported vulnerability chain, not this amount per CVE.
Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.
- One reported chain, not a $75,000 award for each CVE
- Broader project found seven bugs; source attributes this award to the camera exploit
- The researcher's page has no explicit publication date
- Publication date is unknown in the primary source, so recency is explicitly uncertain.
Recorded timeline
- Fixed
- 2020-01-28explicit · Safari 13.0.5 vendor release date; the advisory entry was added February 6.
Sources and provenance
- Safari origin confusion undermined stored media permissions Ryan Pickren · reviewed 2026-10-02
- Apple security release advisory Apple · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.