/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple announces a “major evolution” of the Apple Security Bounty program, doubling its top award to $2M for exploit chains that could be abused for spyware

With the mercenary spyware industry booming, Apple VP Ivan Krstić tells WIRED that the company is also offering bonuses …

Wired Lily Hay Newman

Context & Ripple Effects

Apple’s bounty program has moved from a small invite-only launch to broader platform coverage and a $1 million maximum in 2019. The latest change concentrates its strongest incentive on exploit chains with spyware relevance.

By 2022, Apple said it had paid roughly $20 million in researcher rewards, including multiple six-figure awards. That record of high-impact payouts makes the larger ceiling a meaningful escalation in how Apple tries to surface the most consequential vulnerabilities.

First-order effects

  • Security researchers who find qualifying spyware-usable exploit chains now have a potential $2 million disclosure reward from Apple, increasing the financial incentive to report those flaws to the company.
  • Apple can direct more attention toward the exploit paths most relevant to mercenary spyware and prioritize fixes for them through its Security Bounty program.

Second-order effects

  • The higher ceiling raises the opportunity cost for researchers weighing responsible disclosure against other routes for monetizing high-value exploit research, though the effect will depend on award rules and payment reliability.
  • Other platform vendors may face pressure to reassess whether their top bounty tiers adequately attract research into chained, high-impact vulnerabilities.

Third-order effects

  • If major platforms keep paying more for exploit chains, vulnerability disclosure programs could become a more central counterweight to markets for dual-use offensive research.
  • The move points toward security incentives being designed around real-world abuse potential rather than isolated bug severity, potentially changing how vendors define and reward critical findings.

The trend: Platform owners are increasingly using premium bounty rewards to channel high-end exploit research away from spyware-relevant abuse and into coordinated remediation.

Discussion

  • @arinwaichulis Arin Waichulis on x
    🚨 Apple's Bounty Program just got a massive upgrade: top awards increasing BIGLY (now up to $2M for zero-click exploits), new “Target Flags” system pays researchers immediately upon verification, and now pays out $1K for low-impact finds Coming November https://9to5mac.com/...
  • @jsrailton John Scott-Railton on bluesky
    NEW: fresh trouble for mercenary spyware companies like NSO.  —  #Apple is launching fat bounties on the zero-click exploits that feed the supply chain behind products like Pegasus & Paragon's Graphite.  —  With bonuses, exploit developers can land $5 million payouts.  —  securit…
  • @kimzetter Kim Zetter on bluesky
    Apple announces new payouts for certain types of bugs - company will pay up to $2 million for anyone disclosing a chain of bugs that could be abused for spyware like Pegasus, as well as bonus awards for exploits that can bypass Lockdown Mode or are found while Apple software is s…
  • @lhn Lily Hay Newman on bluesky
    As Apple expands its bug bounty, I spoke with VP Ivan Krstić about the significance + recent big swings like Memory Integrity Enforcement.  These steps protect all users, but particularly those targeted by spyware: “We feel a great moral obligation to defend those users” www.wire…
  • @couts Andrew Couts on bluesky
    NEW: Apple is offering up to $2 million for exploits that can be used to infect iPhones with spyware, and bonuses for exploits used to bypass Lockdown Mode that bring total possible awards for a bug bounty to $5 million. @lhn.bsky.social reports: www.wired.com/story/apple-...
  • @Migueldeicaza@mastodon.social Miguel de Icaza on mastodon
    When you are an Apple security researcher, Christmas comes early on November 2025:  —  https://security.apple.com/...