Apple Launches Security Research Device Program to Give Bug Hunters Deeper OS Access to Find Vulnerabilities - MacRumors
Skip to Content

Apple Launches Security Research Device Program to Give Bug Hunters Deeper OS Access to Find Vulnerabilities

Apple is today launching a new Apple Security Research Device Program that's designed to provide security researchers with special iPhones that are dedicated to security research with unique code execution and containment policies.

applesecuritydevice
Apple last year said it would be providing security researchers with access to "special" iPhones that would make it easier for them to find security vulnerabilities and weaknesses to make iOS devices more secure, which appears to be the program that's rolling out now.

The iPhones that Apple is providing to security researchers are less locked down than consumer devices and will make it easier to find serious security vulnerabilities.

Apple says the Security Research Device (SRD) offers shell access and can run any tools or entitlements, but other than that, it behaves similarly to a standard iPhone. SRDs are provided to security researchers on a 12-month renewable basis and remain Apple property. Bugs discovered with the SRD must be "promptly" reported to Apple or a relevant third-party.

If you use the SRD to find, test, validate, verify, or confirm a vulnerability, you must promptly report it to Apple and, if the bug is in third-party code, to the appropriate third party. If you didn't use the SRD for any aspect of your work with a vulnerability, Apple strongly encourages (and rewards, through the Apple Security Bounty) that you report the vulnerability, but you are not required to do so.

If you report a vulnerability affecting Apple products, Apple will provide you with a publication date (usually the date on which Apple releases the update to resolve the issue). Apple will work in good faith to resolve each vulnerability as soon as practical. Until the publication date, you cannot discuss the vulnerability with others.

Apple is accepting applications for the Security Research Device Program. Requirements include being in the Apple Developer Program, and having a track record finding security issues on Apple platforms.

Those that participate in the program will have access to extensive documentation and a dedicated forum with Apple engineers, with Apple telling TechCrunch that it wants the program to be a collaboration.

The Security Research Device Program will run alongside the bug bounty program, and hackers can file bug reports with Apple and receive payouts of up to $1 million, with bonuses possible for the worst vulnerabilities.

Popular Stories

apple price hike

Apple Just Increased Prices on MacBooks, iPads, and More

Thursday June 25, 2026 5:44 am PDT by
Apple today dramatically increased device prices across multiple product lines. Subscribe to the MacRumors YouTube channel for more videos. After temporarily taking it down earlier today, Apple's online store is back up with a series of product price increases. The changes are as follows: HomePod mini: $129, up from $99 (+$30) HomePod: $349, up from $299 (+$50) Apple TV: $199, up from...
iphone 17 ceramic shield

2027 iPhone 18 and iPhone 18e to Get 9GB RAM and A20 Chip

Friday June 26, 2026 9:57 am PDT by
The lower-end iPhone 18 models set to launch in spring 2027 will feature 9GB DRAM, up from 8GB, according to Apple analyst Ming-Chi Kuo. Kuo says the A20 chip Apple plans to use for the devices will have 1.5GB x 6 dies for a total of 9GB RAM, instead of 2GB x 4 dies as the current lower-end iPhone 17 models use. By lower-end iPhones, Kuo is likely referencing the iPhone 18 and the iPhone...
Mac Studio Feature

M5 Ultra Mac Studio Could Launch in 2026 With Up to 768GB of RAM

Thursday June 25, 2026 2:30 pm PDT by
Despite price increases across the Mac line, Apple is still planning to release a new Mac Studio as soon as this year, reports Bloomberg. Apple plans to introduce a new M5 Ultra chip as the final option in the M5 family before it transitions to the M6, M7, M7 Pro, and M7 Max. The M5 Ultra will come in a new version of the Mac Studio, which hasn't been updated since March 2025. The Mac...

Top Rated Comments

Vanilla35 Avatar
78 months ago


Attachment Image
Score: 12 Votes (Like | Disagree)
78 months ago
Every government in the world just joined the Apple Developer Program.
Score: 7 Votes (Like | Disagree)
tehabe Avatar
78 months ago
The big issue is, that Apple controls everything in this programme. Apple could decide not to fix an issue and nobody would know because only Apple decides when to release the information. That is btw the reason why Google's Project Zero won't join this programme, it is against their 90 days publication policy.
Score: 3 Votes (Like | Disagree)
SecuritySteve Avatar
78 months ago

How is this different than the crash logs we already have in iOS?
There's a huge difference. Right now there's no way to inspect the file system to see if there was a successful breach, and crash logs only contain a stack trace and memory snapshot of application. With this kit you have full access to the device that normally would be protected. This lets you probe more sensitive areas such as Secure Enclave.

It also lets you do more detailed API testing and fuzzing as root on the iPhone, similar to what Google Project Zero's Ian Beer does.
Score: 2 Votes (Like | Disagree)
78 months ago
Nice to see. Just keep making security better on it Apple.
Score: 2 Votes (Like | Disagree)
78 months ago
Not being able to break in is kind of a security issue. :)
Score: 1 Votes (Like | Disagree)