We had lengthy discussions explaining the bug to Apple. It was clear to us the bug was new to Apple Product Security. After 5 months, they informed us that the report was treated as a duplicate and it was addressed.
We just got this update for CVE-2026-28910: No bounty
You can read the full blog post (aka charity work for a 4-trillion-dollar company) highlighting this bug here:


