Apple announces a “major evolution” of the Apple Security Bounty program, doubling its top award to $2M for exploit chains that could be abused for spyware
$2M Top Payout Usman Qureshi / iPhone in Canada : Apple Doubles Security Bounty Rewards to $2 Million Bill Toulas / BleepingComputer : Apple now offers $2 million for zero-click RCE vulnerabilities Tim Hardwick / MacRumors : Apple Introduces $2M Bug Bounty for Spyware-Level Exploits Usama Jawad / Neowin : Apple will pay you up to $5 million for reporting a security flaw in its products Michael Simon / Macworld : If you find an Apple vulnerability, you could walk away with $2M iClarified : Apple Doubles Top Security Bounty to $2 Million to Combat Mercenary Spyware Jonny Evans / Computerworld : Apple doubles security bounty at Hexagon 2025 Zeljka Zorz / Help Net Security : Apple offers $2 million for zero-click exploit chains Sam Sabin / Axios : Apple offers hackers bug bounty of up to $2 million Michael Kan / PCMag : Find a Flaw, Earn Millions: Apple Gives Bug Bounty Payouts a Significant Boost William Gallagher / AppleInsider : Apple is about to give more generous payouts from its Bug Bounty Program Chance Miller / 9to5Mac : Apple announces ‘major evolution’ of its Security Bounty program: $2 million top award, more Amar Ćemanović / CyberInsider : Apple Offers $2 Million Bounty for Remote Zero-Click Exploits MacDailyNews : Apple will pay up to $2 million bug bounty reward Eduard Kovacs / SecurityWeek : Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid To Date Dennis Sellers / MacTech.com : Apple has announced a “major evolution” of its Security Bounty program, which will go into effect next month. … X: John Scott-Railton / @jsrailton : WOW: @Apple donating a thousand new #iPhone17 s to civil society at-risk from mercenary spyware. Good. This will help get Apple's most secure devices to where they need to be.. Truth is: those at the greatest risk from spyware are often least able to afford more secure phones [image] John Scott-Railton / @jsrailton : NEW: fresh trouble for mercenary spyware companies like NSO Group. @Apple launching substantial bounties on the zero-click exploits that feed the supply chain behind products like Pegasus & Paragon's Graphite. With bonuses, exploit developers can hit $5 million payouts. 1/ [image] John Scott-Railton / @jsrailton : @Apple 4/ It's also a clear signal that Apple announced this at @hexacon_fr, a major offensive security conference. https://x.com/... John Scott-Railton / @jsrailton : 3/ If I contemplating investing in spyware companies I'd want to carefully evaluate whether their exploit pipeline can match what @apple just threw down. https://security.apple.com/... @hexacon_fr : We're very honored to have Ivan Krstić (@radian) for our opening keynote. Don't miss that! [image] John Scott-Railton / @jsrailton : 2/ Apple is introducing Target Flags which speeds the process of getting exploits found & submitters rewarded. This faster tempo is also a strike against the mercenary spyware ecosystem. And the expanded categories also hit more widely against commercial surveillance vendors. [image] Arin Waichulis / @arinwaichulis : 🚨 Apple's Bounty Program just got a massive upgrade: top awards increasing BIGLY (now up to $2M for zero-click exploits), new “Target Flags” system pays researchers immediately upon verification, and now pays out $1K for low-impact finds Coming November https://9to5mac.com/... Bluesky: Catalin Cimpanu / @campuscodi.risky.biz : Watch out everyone... we're doubling the rewards we almost never pay [embedded post] Kim Zetter / @kimzetter : Apple announces new payouts for certain types of bugs - company will pay up to $2 million for anyone disclosing a chain of bugs that could be abused for spyware like Pegasus, as well as bonus awards for exploits that can bypass Lockdown Mode or are found while Apple software is still in beta testing Lily Hay Newman / @lhn : As Apple expands its bug bounty, I spoke with VP Ivan Krstić about the significance + recent big swings like Memory Integrity Enforcement. These steps protect all users, but particularly those targeted by spyware: “We feel a great moral obligation to defend those users” www.wired.com/story/apple-... Andrew Couts / @couts : NEW: Apple is offering up to $2 million for exploits that can be used to infect iPhones with spyware, and bonuses for exploits used to bypass Lockdown Mode that bring total possible awards for a bug bounty to $5 million. @lhn.bsky.social reports: www.wired.com/story/apple-... Mastodon: Jeff Johnson / @lapcatsoftware@mastodon.social : RE: https://mastodon.online/... A major evolution would be if Apple actually paid people who submitted bugs instead of arbitrarily deciding “nope” Dan Underwood / @danunderwood@mastodon.social : We're updating our bounty program with the top award now set at $2 million for zero-click remote exploit chains. In addition - there are increased awards for proximate wireless attacks, WebKit, and Gatekeeper — https://security.apple.com/... Kim Zetter / @kimzetter@infosec.exchange : Apple has super-sized its bug-bounty program. It will now pay up to $2 million to anyone disclosing a chain of bugs that can be used to install spyware like Pegsus and is also offering bonus awards for bugs that can be used to bypass Lockdown Mode https://security.apple.com/... Miguel de Icaza / @Migueldeicaza@mastodon.social : When you are an Apple security researcher, Christmas comes early on November 2025: — https://security.apple.com/... Thomas Bosboom / @thomasbosboom@infosec.exchange : A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research https://security.apple.com/... Forums: r/cybersecurity : Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits r/apple : A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research r/technews : Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits Lobsters : A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research Msmash / Slashdot : Apple Doubles Its Biggest Bug Bounty Reward To $2 Million Ars OpenForum : Apple ups the reward for finding major exploits to $2 million
Context & Ripple Effects
Apple’s bounty has steadily broadened from a program centered on a few iOS and iCloud exploit areas to a 2019 expansion across Apple’s major operating systems, with the program opened to more researchers and its maximum award lifted to $1 million.
By 2022, Apple said the program had paid roughly $20 million, including multiple six-figure awards for high-impact findings. The new ceiling and faster-verification tools extend that established effort toward the most severe spyware-capable chains.
First-order effects
- Researchers who can document qualifying zero-click remote-code-execution chains now have a substantially larger disclosed-reward path, with specified bonuses potentially raising a single finding’s payout to $5 million.
- Apple adds Target Flags and expands bounty categories, aiming to shorten the path from a researcher’s report to verification and payment while prioritizing protections such as Lockdown Mode.
Second-order effects
- A higher, clearer payout for the most valuable chains raises the economic appeal of reporting them to Apple rather than pursuing other buyers, though the program’s effectiveness will depend on speed and consistency of triage.
- Other platform security teams may face pressure to reassess rewards and reporting workflows for comparable high-impact findings, particularly as Apple’s program moves beyond the earlier record of high-impact six-figure awards.
Third-order effects
- If major vendors pair larger rewards with faster validation, bug bounties could become a more central channel for redirecting dual-use exploit research into coordinated remediation rather than private circulation.
- The durable competition will shift from headline payout size alone to operational credibility: whether vendors can rapidly reproduce, patch, and fairly compensate for complex exploit chains.
The trend: Platform vendors are treating high-end vulnerability disclosure as ecosystem defense, competing on both payouts and the speed of turning researcher intelligence into fixes.