The 14 Year Old Who Found Apple's Bug (And Couldn't Get Apple to Listen)
00:42 · Point of failure
A teenager discovered that Group FaceTime could transmit audio before a call was accepted. His family struggled to report it before it became public. Apple disabled the feature and fixed the call-state logic.

Editions
- Watch
- The episode on YouTube1:49
- Read
- The technical debrief on ZOF.aizof.ai
Incident
- Topics
- vulnerability reporting · privacy · state machines · security
- Point of failure
- There was no easy lane for a regular person holding a critical bug, so a week of emails, calls and a fax went nowhere until the bug went public on its own.
Transcript
The discovery
A 14-year-old found a bug that lets people eavesdrop on any iPhone. His mom spent a week trying to get Apple to pick up. This is The Point of Failure, episode eleven.
Grant Thompson, 14-year-old, Arizona. He's setting up a group FaceTime call to play games with friends, and he notices something impossible. While the call is still ringing, before his friend ever picks up, he can hear him.
Think about what that means. Anyone could call your phone and listen to the room you are standing in while you look at the screen that says ringing. Your phone has answered without you.
Trying to report it
Point of failure
Grant tells his mom, Michele. She does the right thing. She tries to warn Apple. She emails. She calls support. She even sends a fax. Days go by, she gets nowhere because there is no easy lane for a regular person holding a critical bug.
The response
About a week later, the bug goes viral on its own. Now it is a global story. Apple shuts down Group FaceTime at the server within hours, ships a fix, credits Grant by name, pays him a bounty, and contributes to his education. The fix was fast. The listening was fast. It was the reporting that was broken.
A door for the next report
Somewhere out there, the next critical bug has already been found by someone with no badge and no title. The question is whether anyone built them a door.
Every failure has a story. Every story was preventable. I'm Kevin. See you in the next one.
Sources
Related
- 14
The Power Cut in Ghana That Saved Global Shipping
On 27 June 2017 the NotPetya malware destroyed Maersk's global network within minutes, including every domain controller. As Wired reported, one copy survived in the company's Ghana office, offline after a power cut, and it seeded a rebuild the company put at about ten days.
- 13
The Fan Who Fixed a Billion Dollar Game
For seven years GTA Online could take minutes to load. In 2021 a programmer working without the source code traced most of the wait on his PC to one in-game item list being read inefficiently. Rockstar confirmed it, shipped a fix for the PC version and paid a bounty.
- 09
38 Minutes of 'This Is Not a Drill'
On 13 January 2018, Hawaii sent a false ballistic missile alert during a drill. Confusing procedures and inadequate safeguards let it through; the corrective wireless alert took 38 minutes.