Apple Expands Bug Bounty to Macs, Offers Up to $1 Million for Flaws

Apple launches a bug bounty program for macOS, Apple TV, and Apple Watch, offering payouts up to $1 million for the most severe vulnerabilities. The move ends years of frustration from security researchers who previously withheld flaws due to the lack of financial incentives.

Apple finally expands its bug bounty program to include macOS, Apple TV, and Apple Watch, marking the first time the tech giant offers cash rewards for security flaws found on its computers. The company announces this expansion at the Black Hat conference in Las Vegas, nearly three years after introducing a similar program exclusively for iOS devices.

The program addresses long-standing criticisms from security researchers who refuse to report Mac vulnerabilities without financial compensation. Experts like Patrick Wardle previously drop zero-day flaws to protest Apple's previous stance, warning that the lack of a bounty drives researchers to sell bugs to exploit brokers and black market buyers instead.

Alongside extending the program to new devices, Apple significantly increases its maximum payout from $200,000 to $1 million for the most severe exploits. This top reward applies to zero-click, full chain kernel code execution attacks with persistence, representing a major financial incentive for hackers to help protect everyday Apple users.

Read More at the original source →