I submitted some details (nothing technical, just the classification and affected platforms) of my vulnerability to Zerodium. Two days later someone tried to hack into all of my personal accounts and failed due to 2FA, and not many people have the email I used when I communicated with them. I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
I've found other buyers outside the US, but I had ethical concerns and decided against them (at a 300K min loss).
What type of buyers exist who are unable to fix the vulnerability (in this case, who are not Apple or the affected vendor or do not collaborate with Apple, etc.) but might be considered ethical to sell to?
I imagine some people think being rewarded for finding vulnerabilities is unethical entirely, but there seems to be a huge dose of pragmatism around the space.
Alternatively depending on how nationalistic someone feels NSA could be a eithical buyer for them as well.