Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Badges, Bytes and Blackmail

February 7, 2026

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Apple Bug Bounty Payouts Can Now Top $5m
News

Apple Bug Bounty Payouts Can Now Top $5m

Team-CWDBy Team-CWDOctober 13, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Apple has doubled its top award for ethical hacking discoveries to $2m, although security researchers could earn even more if they’re able to unlock bonuses, the tech giant has revealed.

Apple said on Friday that it was increasing the award for “exploit chains that can achieve similar goals as sophisticated mercenary spyware attacks,” to an “unprecedented” sum.

“Our bonus system, providing additional rewards for Lockdown Mode bypasses and vulnerabilities discovered in beta software, can more than double this reward, with a maximum payout in excess of $5m,” the firm continued.

“We’re also doubling or significantly increasing rewards in many other categories to encourage more intensive research. This includes $100,000 for a complete Gatekeeper bypass, and $1m for broad unauthorized iCloud access, as no successful exploit has been demonstrated to date in either category.”

Read more on bug bounty programs: Researcher Finds Five Zero-Days and 20+ Misconfigurations in Salesforce Cloud

The firm said it has already paid $35m to more than 800 security researchers since the launch of the Apple Security Bounty program in 2020.

However, its latest bug bounty announcement can be seen as a response to the growth of commercial spyware activity. Firms like NSO Group and Intellexa produce sophisticated exploits to get their malware on the devices of clients’ targets – often dissidents and journalists.

The challenge has become so acute that governments and tech companies last year signed a joint agreement named the “Pall Mall Process” designed to help tackle the proliferation of commercial spyware.

The UK’s National Cyber Security Centre (NCSC) estimates that the commercial cyber intrusion sector doubles every 10 years.

“The only system-level iOS attacks we observe in the wild come from mercenary spyware – extremely sophisticated exploit chains, historically associated with state actors, that cost millions of dollars to develop and are used against a very small number of targeted individuals,” said Apple.

“While Lockdown Mode and Memory Integrity Enforcement make such attacks drastically more expensive and difficult to develop, we recognize that the most advanced adversaries will continue to evolve their techniques.”

More Rewards on Offer

Apple also announced an expansion of other bounty categories, including “one-click WebKit sandbox escapes.” Successful researchers will get payouts of up to $300,000 for these, while those able to produce “wireless proximity exploits over any radio” could get up to $1m.

The firm is also introducing a new way for researchers to objectively demonstrate exploitability in several popular bounty categories. Those who submit reports under the new “Target Flags” initiative could qualify for faster awards, Apple said.

The news comes a few days after a new hacking competition was announced by cloud security company Wiz, Google Cloud, AWS and Microsoft. Zeroday Cloud will debut at Black Hat London this December.

Image credit: Prathmesh T / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDetour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer
Next Article Scanning Activity on Palo Alto Networks Portals Jump 500% in One Day
Team-CWD
  • Website

Related Posts

News

Badges, Bytes and Blackmail

February 7, 2026
News

Ex-Google Engineer Convicted for Stealing AI Secrets for China Startup

February 7, 2026
News

Substack Confirms Data Breach, “Limited User Data” Compromised

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

When ‘hacking’ your game becomes a security risk

October 17, 2025

Why you should never pay to get paid

September 15, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.