Quote:
Originally Posted by murraypaul
But it wasn't a dummy bomb, it was a genuine bomb, he just didn't explode it.
|
Unfortunately, this. Normally, I think most security researchers tend to inform the company first and only after they don't receive a reply that the company is trying to fix the problem do they make their findings public. Of course, he couldn't have known that his app would pass the app review process unless he submits it and I reckon that was as much part of his test as the actual exploit.