{"id":202832,"date":"2025-10-10T11:46:07","date_gmt":"2025-10-10T11:46:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/202832\/"},"modified":"2025-10-10T11:46:07","modified_gmt":"2025-10-10T11:46:07","slug":"apple-announces-2-million-bug-bounty-reward-for-the-most-dangerous-exploits","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/202832\/","title":{"rendered":"Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits"},"content":{"rendered":"<p>Since launching its bug bounty program nearly a decade ago, <a href=\"https:\/\/www.wired.com\/tag\/apple\/\" rel=\"nofollow noopener\" target=\"_blank\">Apple<\/a> has always touted notable maximum payouts\u2014<a href=\"https:\/\/www.wired.com\/2016\/08\/apples-finally-offering-bug-bounties-highest-rewards-ever\/\" rel=\"nofollow noopener\" target=\"_blank\">$200,000<\/a> in 2016 and <a href=\"https:\/\/www.wired.com\/story\/apple-hacker-iphone-bug-bounty-macos\/\" rel=\"nofollow noopener\" target=\"_blank\">$1 million<\/a> in 2019. Now the company is upping the stakes again. At the Hexacon offensive security conference in Paris on Friday, Apple vice president of security engineering and architecture Ivan Krsti\u0107 announced a new maximum payout of $2 million for a chain of software exploits that could be abused for <a href=\"https:\/\/www.wired.com\/story\/us-spyware-investment\/\" rel=\"nofollow noopener\" target=\"_blank\">spyware<\/a>.<\/p>\n<p class=\"paywall\">The move reflects how valuable exploitable vulnerabilities can be within Apple&#8217;s highly protected mobile environment\u2014and the lengths the company will go to to keep such discoveries from falling into the wrong hands. In addition to individual payouts, the company&#8217;s bug bounty also includes a bonus structure, adding additional awards for exploits that can bypass its <a href=\"https:\/\/www.wired.com\/story\/apple-lockdown-mode-hands-on\/\" rel=\"nofollow noopener\" target=\"_blank\">extra secure Lockdown Mode<\/a> as well as those discovered while Apple software is still in its beta testing phase. Taken together, the maximum award for what would otherwise be a potentially catastrophic exploit chain will now be $5 million. The changes take effect next month.<\/p>\n<p class=\"paywall\">\u201cWe are lining up to pay many millions of dollars here, and there\u2019s a reason,\u201d Krsti\u0107 tells WIRED. \u201cWe want to make sure that for the hardest categories, the hardest problems, the things that most closely mirror the kinds of attacks that we see with mercenary spyware\u2014that the researchers who have those skills and abilities and put in that effort and time can get a tremendous reward.&#8221;<\/p>\n<p class=\"paywall\">Apple says that there are more than 2.35 billion of its devices active around the world. The company&#8217;s bug bounty was <a href=\"https:\/\/www.wired.com\/2016\/08\/apples-finally-offering-bug-bounties-highest-rewards-ever\/\" rel=\"nofollow noopener\" target=\"_blank\">originally<\/a> an invite-only program for prominent researchers, but since opening to the public in 2020, Apple says that it has awarded more than $35 million to more than 800 security researchers. Top-dollar payouts are very rare, but Krsti\u0107 says that the company has made multiple $500,000 payouts in recent years.<\/p>\n<p class=\"paywall\">In addition to higher potential rewards, Apple is also expanding the bug bounty&#8217;s categories to include certain types of one-click \u201cWebKit\u201d browser infrastructure exploits as well as wireless proximity exploits carried out with any type of radio. And there is even a new offering known as \u201cTarget Flags\u201d that puts the concept of <a href=\"https:\/\/www.wired.com\/story\/china-hacking-competition-real-victim\/\" rel=\"nofollow noopener\" target=\"_blank\">capture the flag hacking competitions<\/a> into real-world testing of Apple&#8217;s software to help researchers demonstrate the capabilities of their exploits quickly and definitively.<\/p>\n<p class=\"paywall\">Apple&#8217;s bug bounty is just one of many long-term investments aimed at reducing the prevalence of dangerous vulnerabilities or blocking their exploitation. For example, after more than five years of work, the company announced a security protection last month in the <a href=\"https:\/\/www.wired.com\/review\/apple-iphone-17-pro-and-iphone-17-pro-max\/\" rel=\"nofollow noopener\" target=\"_blank\">new iPhone 17 lineup<\/a> that <a href=\"https:\/\/www.wired.com\/story\/apple-iphone-17-memory-integrity-enforcement\/\" rel=\"nofollow noopener\" target=\"_blank\">aims to nullify the most frequently exploited class of iOS bugs<\/a>. Known as Memory Integrity Enforcement, the feature is a big swing aimed at protecting a small minority of the most vulnerable and highly targeted groups around the world\u2014including activists, journalists, and politicians\u2014while also adding defense for all users of new devices. To that end, the company announced on Friday that it will donate a thousand iPhone 17s to rights groups that work with people at risk of facing targeted digital attacks.<\/p>\n<p class=\"paywall\">\u201cYou can say, well, that seems like a very large effort to protect only that very small number of users that are being targeted by mercenary spyware, but there is just this incontrovertible track record described by journalists, tech companies, and civil society organizations that these technologies are constantly being abused,\u201d Krsti\u0107 says. \u201cAnd we feel a great moral obligation to defend those users. Despite the fact that the vast majority of our users will never be targeted by anything like this, this work that we did will end up increasing protection for everyone.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Since launching its bug bounty program nearly a decade ago, Apple has always touted notable maximum payouts\u2014$200,000 in&hellip;\n","protected":false},"author":2,"featured_media":202833,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[1337,64,63,126398,284,31125,10664,1340,1341,4206,105],"class_list":["post-202832","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-apple","tag-au","tag-australia","tag-bug-bounty","tag-cybersecurity","tag-encryption","tag-hacks","tag-ios","tag-iphone","tag-security","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/202832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=202832"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/202832\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/202833"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=202832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=202832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=202832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}