Apple Introduces $2M Bug Bount... Note

Apple Introduces $2M Bug Bounty for Spyware-Level Exploits

Apple has significantly enhanced its bug bounty program, doubling the top reward to $2 million for sophisticated exploit chains resembling mercenary spyware attacks. With additional bonuses for Lockdown Mode bypasses and beta software vulnerabilities, total payouts could surpass $5 million. This program now prioritizes complete exploit chains over isolated bugs, acknowledging how real-world attacks combine vulnerabilities. Rewards for remote entry exploit chains have seen substantial increases. A new "Target Flags" system, inspired by capture-the-flag games, allows researchers to prove achieved access levels like code execution. Successful flag captures will enable immediate bounty notifications and faster payments after Apple's validation, eliminating past waiting periods for software fixes. These program updates will be effective from November 2025. New categories include up to $300,000 for one-click WebKit sandbox escapes and up to $1 million for wireless proximity exploits. A macOS Gatekeeper bypass now offers a $100,000 reward. Since its 2020 launch, Apple's program has paid over $35 million to more than 800 researchers.
CdXz5zHNQW_i0U4T0pbmr.jpeg