Apple Officially Launches Public Bug Bounty Program Covering All Apple Software

Apple today officially opened its bug bounty program to all security researchers, after the company announced the expansion plan at the Black Hat conference in Las Vegas earlier this year.

apple bug bounty image
Prior to now, Apple's bug bounty program was invitation-based and non-iOS devices were not included. As reported by ZDNet, from today any security researcher who locates bugs in iOS, macOS, tvOS, watchOS, or iCloud will be eligible to receive a cash payout for disclosing the vulnerability to Apple.

Apple has also increased the maximum size of the bounty from $200,000 per exploit to $1 million depending on the nature of the security flaw. A zero-click kernel code execution with persistence will earn the maximum amount.

Apple says it will add a 50 percent bonus on top of the standard payout for bugs found in beta software, which allows the company to nix the issue before the OS version goes public. It is also offering the same bonus for so-called "regression bugs" – these are bugs that Apple has patched in the past but which have been accidentally reintroduced in a later version of the software.

Apple has published more information on its website detailing the bug bounty program's rules, as well as a full breakdown of the rewards being offered to researchers based on the exploits they uncover.

When submitting reports, researchers must include a detailed description of the issue, an explanation of the state of the system when the exploit works, and enough information for Apple to reliably reproduce the issue.

Next year, Apple plans to provide vetted and trusted security researchers and hackers with "dev" iPhones, or special iPhones that provide deeper access to the underlying software and operating system that will make it easier for vulnerabilities to be discovered.

These iPhones are being provided as part of Apple's forthcoming iOS Security Research Device Program, which aims to encourage additional security researchers to disclose vulnerabilities, ultimately leading to more secure devices for consumers.

Popular Stories

Apple AI Command Center Concept Mock 3

Apple Expected to Launch This All-New Device Next Year

Wednesday November 27, 2024 1:05 pm PST by
Apple is expected to kick off 2025 by launching an all-new smart home hub, also referred to as a "command center," as early as March. The hub is expected to feature around a six-inch display that can be attached to a tabletop base with a speaker, or mounted on a wall. The device is said to run a new "homeOS" operating system with a customizable widget-focused home screen, and it is expected...
iOS 18

Here Are Apple's Full Release Notes for iOS 18.2

Thursday December 5, 2024 11:48 am PST by
Apple seeded the release candidate version of iOS 18.2 today, which means it's going to see a public launch imminently. Release candidates represent the final version of new software that will be provided to the public should no last minute bugs be found, and Apple includes release notes with the RC launch. The iOS 18.2 release notes provide a look at all of the new features that are coming...
Whatsapp Feature

WhatsApp to Drop Support for These iPhones Starting May 2025

Monday December 2, 2024 2:57 am PST by
WhatsApp is set to end support for iOS versions older than iOS 15.1 from May next year, removing the chat platform's compatibility with several iPhone models in the process. From May 5, 2025, WhatsApp will no longer be compatible with iPhone 5s, iPhone 6, and iPhone 6 Plus models. Users with those devices won't be able to access the encrypted chat service after the specified date unless they ...
Flip iPhone Thumb 1

Apple's 2026 Foldable iPhone Could Reinvigorate Stalling Market

Monday December 2, 2024 4:04 pm PST by
The foldable smartphone market has stalled with customer interest in foldables waning, but that could change when Apple debuts a foldable iPhone, according to display analyst Ross Young. In a report on the current foldable smartphone market, Young says that Apple is expected to "enter the foldable market" in the second half of 2026. Apple's "dominant position in flagship smartphones" could...
airpods pro 2 gradient

AirPods Pro 3 Expected Next Year: Here's What We Know

Thursday November 28, 2024 3:30 am PST by
Despite being released over two years ago, Apple's AirPods Pro 2 continue to dominate the wireless earbud market. However, with the AirPods Pro 3 expected to launch sometime in 2025, anyone thinking of buying Apple's premium earbuds may be wondering if the next generation is worth holding out for. Apart from their audio and noise-canceling performance, which are generally regarded as...
iPhone 17 Pro Dual Tone Rectangle Feature 1

iPhone 17 Pro Already Rumored to Have These 8 New Features

Wednesday November 27, 2024 12:19 pm PST by
While the iPhone 17 Pro and iPhone 17 Pro Max are not expected to launch for 10 more months, there are already plenty of rumors about the devices. An imaginative iPhone 17 Pro concept based on rumors Below, we recap key changes rumored for the iPhone 17 Pro models so far: Aluminum frame: iPhone 17 Pro models are rumored to have an aluminum frame, whereas the iPhone 15 Pro and iPhone 16 Pro ...

Top Rated Comments

Justin Cymbal Avatar
65 months ago
Definitely incentivizes people to find vulnerabilities the legit way while also getting compensated

Huge increase of the maximum payout too! $200,000 to $1 million

I'm glad that Apple is finally doing this program...
Score: 21 Votes (Like | Disagree)
andycarver Avatar
65 months ago
I got want all ready: Computer is buggy.
Reproductive steps: Install macOS Catalina.
Score: 10 Votes (Like | Disagree)
urtules Avatar
65 months ago
This is great news, sure it will cost a lot of money to run, but it will pay off in security and loyalty. It was always a mystery why only iOS devises were open for bounty. I suppose Apple wanted to finish Catalina first and prevent more exploits with stronger Catalina security features.
Score: 9 Votes (Like | Disagree)
dogslobber Avatar
65 months ago

Yeah great idea. Let’s put a billion Mac and iOS users at risk to satisfy your ridiculous and uninformed notion that security risks only occur due to laziness and lack of testing.
This is a pretty uneducated response.
Score: 8 Votes (Like | Disagree)
adrianlondon Avatar
65 months ago
Dear Apple,
MAIL!

*retires*
Score: 6 Votes (Like | Disagree)
Steve121178 Avatar
65 months ago
Should have happened years ago. I expect a lot of people are going to earn very well from this.
Score: 6 Votes (Like | Disagree)