Apple Expands Bug Bounty Program, Offers Up to $1 Million for Flaws
Apple is expanding its bug bounty program to cover macOS, watchOS, tvOS, and iCloud, offering rewards up to $1 million. The company also plans to provide researchers with special iPhones to aid in security testing.
Apple is significantly expanding its bug bounty program to cover macOS, watchOS, tvOS, and iCloud, showing a strong commitment to cybersecurity. The company now offers rewards up to $1 million for researchers who discover and disclose severe security flaws. Additionally, Apple provides special iPhones to security experts to help them find vulnerabilities before malicious hackers do.
This expansion builds upon the original iOS-only program that launched in 2016. The massive $1 million payout is specifically reserved for iOS flaws that allow an attacker to gain complete access to a device without any physical interaction. Meanwhile, flaws in the newly included operating systems earn researchers up to $200,000, and a new $500,000 tier exists for bugs that expose user data.
The broadened scope of this program comes after years of requests from the security community. Previously, researchers sometimes withhold information about discovered bugs due to the lack of financial incentive on non-iOS platforms. By extending these bounties across all of its major software ecosystems, Apple aims to encourage prompt disclosure and strengthen its overall product security.