Six researchers found dozens of vulnerabilities in Apple's infrastructure over a three-month period that allowed them to access, among other things, source code, users 'iCloud accounts, internal applications, employee sessions, and users' private data.
Of the total of 55 vulnerabilities reported by Sam Curry, Brett Buerhaus, Ben Sadeghipour, Samuel Erb and Tanner Barnes, 11 were identified as critical. These vulnerabilities allowed the researchers to execute arbitrary code on Apple systems, gain administrative access to an internal application, take over user accounts, steal Apple's Identity and Access Management (IAM) keys from Amazon Web Services, take over users' iCloud accounts, and access source code from Amazon Web Services. Get Apple Projects.