A zero-click vulnerability in macOS allowed attackers to send malicious calendar invites to victims, potentially stealing sensitive data without user interaction. The exploit chain had five steps and was reportedly fixed by Apple, but the researcher who discovered it has not yet received a bounty payment. The vulnerability was serious enough that it could have been sold to malicious actors for a significant amount of money. The researcher's experience highlights the challenges of working with companies to disclose and fix vulnerabilities.