Apple Introduces $2M Bug Bounty for Spyware-Level Exploits

Apple has announced a major overhaul of its bug bounty program that doubles the top reward to $2 million for exploit chains that can match the sophistication of mercenary spyware attacks.

bug security vulnerability issue fix larry
With bonuses for Lockdown Mode bypasses and vulnerabilities found in beta software, Apple says its total payouts could exceed $5 million. The company claims this represents "the largest payout offered by any bounty program."

The program now places greater emphasis on complete exploit chains rather than individual vulnerabilities, reflecting the reality that real-world attacks typically chain multiple bugs together. The rewards for remote-entry vectors have also been substantially increased, although categories not commonly seen in actual attacks will receive lower payouts.

As part of the overhaul, Apple is introducing "Target Flags," which are inspired by capture-the-flag games. When a researcher successfully exploits a vulnerability, they can capture a specific flag that proves exactly what level of access they achieved, such as code execution or arbitrary read/write capabilities.

These flags can be verified by Apple, so researchers who submit reports using them can receive notification of their bounty award immediately after Apple validates the captured flag. The payment is also issued in an upcoming payment cycle, meaning researchers won't have have to wait until Apple releases a software fix, which can take months. Previously, researchers often had to wait for Apple to patch a vulnerability before receiving payment.

The updated program comes into effect from November 2025. Apple is also expanding categories to include one-click WebKit sandbox escapes worth up to $300,000 and wireless proximity exploits over any radio worth up to $1 million. A complete Gatekeeper bypass on macOS now earns $100,000.

More information on the changes can be found on Apple's Security Research website. Apple says it has paid out over $35 million to more than 800 researchers since launching the public program in 2020.

Popular Stories

Apple Logo Zoomed

Tim Cook Teases Plans for Apple's Upcoming 50th Anniversary

Thursday February 5, 2026 12:54 pm PST by
Apple turns 50 this year, and its CEO Tim Cook has promised to celebrate the milestone. The big day falls on April 1, 2026. "I've been unusually reflective lately about Apple because we have been working on what do we do to mark this moment," Cook told employees today, according to Bloomberg's Mark Gurman. "When you really stop and pause and think about the last 50 years, it makes your heart ...
wwdc sans text feature

Apple Rumored to Announce New Product on February 19

Thursday February 5, 2026 12:22 pm PST by
Apple plans to announce the iPhone 17e on Thursday, February 19, according to Macwelt, the German equivalent of Macworld. The report, citing industry sources, is available in English on Macworld. Apple announced the iPhone 16e on Wednesday, February 19 last year, so the iPhone 17e would be unveiled exactly one year later if this rumor is accurate. It is quite uncommon for Apple to unveil...
Finder Siri Feature

Why Apple's iOS 26.4 Siri Upgrade Will Be Bigger Than Originally Promised

Friday February 6, 2026 3:06 pm PST by
In the iOS 26.4 update that's coming this spring, Apple will introduce a new version of Siri that's going to overhaul how we interact with the personal assistant and what it's able to do. The iOS 26.4 version of Siri won't work like ChatGPT or Claude, but it will rely on large language models (LLMs) and has been updated from the ground up. Upgraded Architecture The next-generation...
iOS 26

iOS 26.3 and iOS 26.4 Will Add These New Features to Your iPhone

Tuesday February 3, 2026 7:47 am PST by
While the iOS 26.3 Release Candidate is now available ahead of a public release, the first iOS 26.4 beta is likely still at least a week away. Following beta testing, iOS 26.4 will likely be released to the general public in March or April. Below, we have recapped known or rumored iOS 26.3 and iOS 26.4 features so far. iOS 26.3 iPhone to Android Transfer Tool iOS 26.3 makes it easier...
iphone 17 pro dark blue 1

iPhone 18 Pro Max Rumored to Deliver Next-Level Battery Life

Friday February 6, 2026 5:14 am PST by
The iPhone 18 Pro Max will feature a bigger battery for continued best-in-class battery life, according to a known Weibo leaker. Citing supply chain information, the Weibo user known as "Digital Chat Station" said that the iPhone 18 Pro Max will have a battery capacity of 5,100 to 5,200 mAh. Combined with the efficiency improvements of the A20 Pro chip, made with TSMC's 2nm process, the...

Top Rated Comments

neuropsychguy Avatar
17 weeks ago
This is a great program and these updates make it much more enticing to people to find exploits. It's good to see Apple's focus on improving security.
Score: 20 Votes (Like | Disagree)
tyranne201 Avatar
17 weeks ago
iOS 26 is the biggest exploit. award me now.
Score: 19 Votes (Like | Disagree)
Macusercom Avatar
17 weeks ago
Great program, worst execution. There have been so many exploits that have been disclosed and those who find it do not get even remotely what Apple promises them. This is the reason many exploits remain hidden and get sold to higher bidders
Score: 16 Votes (Like | Disagree)
Apple-achian Avatar
17 weeks ago
This is why I trust Apple with my personal data.
Score: 14 Votes (Like | Disagree)
Mac Fly (film) Avatar
17 weeks ago

This is why I trust Apple with my personal data.
[TABLE]
[TR]
[TH]Company[/TH]
[TH]Program Name[/TH]
[TH]Max Reward (USD)[/TH]
[TH]Notes[/TH]
[/TR]
[TR]
[TD]Apple[/TD]
[TD]Apple Security Bounty[/TD]
[TD]$2,000,000[/TD]
[TD]For zero-click spyware exploit chains (effective Nov 2025); previously $1M.[/TD]
[/TR]
[TR]
[TD]Google[/TD]
[TD]Vulnerability Reward Program[/TD]
[TD]$1,500,000[/TD]
[TD]For full-chain zero-click RCE in Android; up to $3.1M for Chrome sandbox escapes.[/TD]
[/TR]
[TR]
[TD]Microsoft[/TD]
[TD]Microsoft Bounty Programs[/TD]
[TD]$250,000[/TD]
[TD]For critical RCE in Hyper-V or Azure; varies by product (e.g., $100K+ for Edge).[/TD]
[/TR]
[TR]
[TD]Meta[/TD]
[TD]Meta Bug Bounty[/TD]
[TD]$300,000[/TD]
[TD]For mobile RCE exploits; focuses on privacy/compromise in apps like Facebook/Instagram.[/TD]
[/TR]
[TR]
[TD]Intel[/TD]
[TD]Intel Bug Bounty[/TD]
[TD]$100,000[/TD]
[TD]For critical hardware RCE; lower for software-only issues.[/TD]
[/TR]
[/TABLE]

Honestly I trust none of them. Fully, no way.
Score: 12 Votes (Like | Disagree)
WarmWinterHat Avatar
17 weeks ago

Can you give some examples of those?
https://9to5mac.com/2025/07/31/apple-security-bounties-pay-up-to-2m-but-it-only-paid-1k-for-a-critical-bug/
Score: 10 Votes (Like | Disagree)