
In 2017, I disclosed CVE-2017-2458 to Apple. The actual finding took 3 days of focused testing. The disclosure process took 4 months. What I remember most isn't the CVE number. It's the 40+ hours of reconnaissance before I even had a target. Manually mapping endpoints. Tracing auth flows. Looking for the seam. That's the part that doesn't make it into writeups. And it's the part that AI changes completely. It changes the setup. When I started building, I had one thesis: if we can give a human pentester 40 extra hours per engagement, not by replacing their judgment, but by eliminating their groundwork, the findings get better. More time on the interesting problem. Less on the scaffolding.
Post summary
The author recounts the 2017 disclosure of CVE‑2017‑2458 to Apple, emphasizing the time invested and investigative process, without providing technical or exploit details.
