Yes, to:
- Apple
- FreeBSD
- GhostBSD
- Mozilla
- various other projects, mostly in GitHub.
I have a CVE to my name. This does not make me a security expert.
Apple downplayed the impact of the CVE. It would have made great headlines, if I had chosen to make noises about it. I shared credit with the research centre for which I worked – not because anyone else was actively involved; I gave credit because it seemed the right thing to do. In a nutshell, it was a place where innovation flourished, people had a great mindset. No-one knew a thing about the report, until an eagle-eyed colleague in a different part of the organisation spotted my name.
A privacy and security issue that was, debatably, far worse was reported, but never properly acknowledged by Apple. After a few years, I let the cat out of the bag.