Apple doubles its biggest bug bounty reward to $2 million

Apple is updating its Security Bounty program this November to offer some of the highest rewards in the industry. It has doubled its top award from $1 million to $2 million for the discovery of "exploit chains that can achieve similar goals as sophisticated mercenary spyware attacks" and which requires no user interaction. But the maximum possible payout can exceed $5 million dollars for the discovery of more critical vulnerabilities, such as bugs in beta software and Lockdown Mode bypasses. Lockdown Mode is an upgraded security architecture in the Safari browser. 

In addition, the company is rewarding the discovery of exploit chains with one-click user interaction with up to $1 million instead of just $250,000. The reward for attacks requiring physical proximity to devices can now also go up to $1 million, up from $250,000, while the maximum reward for attacks requiring physical access to locked devices has been doubled to $500,000. Finally, researchers "who demonstrate chaining WebContent code execution with a sandbox escape can receive up to $300,000." Apple's VP for security engineering and architecture Ivan Krstić told Wired that the company has awarded over $35 million to more than 800 security researchers since it introduced and expanded the program over the past few years. Apparently, top-dollar payouts are very rare, but Apple has made multiple $500,000 payouts. 

The company said in its announcement that the only system-level iOS attacks it has observed in the wild came from mercenary spyware, which are historically associated with state actors and typically used to target specific individuals. It said its new security features like Lockdown Mode and Memory Integrity Enforcement, which combats memory corruption vulnerabilities, can make mercenary attacks more difficult to pull off. However, bad actors will continue evolving their techniques, and Apple is hoping that updating its bounty program with bigger payouts can "encourage highly advanced research on [its] most critical attack surfaces despite the increased difficulty."

This article originally appeared on Engadget at https://www.engadget.com/big-tech/apple-doubles-its-biggest-bug-bounty-reward-to-2-million-102844667.html?src=rss

Read more @ Engadget

Latest posts

NYT Connections hints and answers for Thursday, October 16 (game #858)

Looking for a different day?A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people...

Quordle hints and answers for Thursday, October 16 (game #1361)

Looking for a different day?A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are...

Apple TV is the only major streaming service without an ad-supported tier, but that might change

Apple's senior vice president of services has weighed in on the streaming service's name changeHis comments point towards some major changes for Apple TV, especially...

Apple unveils an M5-powered iPad Pro and makes the update all about AI

Apple has unveiled a new M5-powered iPad ProIt's promising big leaps in performanceA possible major update in AI operationsApple's best and thinnest iPad is...

Why more than half of AI projects could fail in 2026

In 2025, to borrow a phrase: the AI revolution is already here; it's just not evenly distributed. While individuals are seeing productivity gains from...

Apple just upgraded the Vision Pro with the M5 chip, and a ‘Dual Knit Band’ that looks way more comfortable

Apple just upgraded the Vision Pro for the first timeIt's not a redesign, but the M5 chip is now under the hoodThere's also a...

UK spy agency warns politicians: ‘You are a potential target’

MI5 warns UK politicians of espionage threats from China, Russia, Iran, and North KoreaThreat actors use phishing, blackmail, and relationship-building to manipulate and recruit...

Jordan’s Discord fans flock to VPNs to defeat sudden outage

Registrations for Proton VPN Free in Jordan spiked after Discord went offlineGovernment-imposed bans are increasingly resulting in VPN signup surgesJordan’s Discord users have found...

Google’s new ‘Help Me Schedule’ lets Gemini coordinate your calendar

New AI features are coming for Google Calendar'Help me Schedule' looks to make meetings a smoother experienceThe feature is only available for meetings with...

Motorola is making a super-thin phone, and I actually think that’s a huge deal

Motorola has revealed the Moto X70 AirIt’s a super thin phone that will compete with the iPhone Air and Samsung Galaxy S25 Edge The...