/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Apple announces a “major evolution” of the Apple Security Bounty program, doubling its top award to $2M for exploit chains that could be abused for spyware

$2M Top Payout Usman Qureshi / iPhone in Canada : Apple Doubles Security Bounty Rewards to $2 Million Bill Toulas / BleepingComputer : Apple now offers $2 million for zero-click RCE vulnerabilities Tim Hardwick / MacRumors : Apple Introduces $2M Bug Bounty for Spyware-Level Exploits Usama Jawad / Neowin : Apple will pay you up to $5 million for reporting a security flaw in its products Michael Simon / Macworld : If you find an Apple vulnerability, you could walk away with $2M iClarified : Apple Doubles Top Security Bounty to $2 Million to Combat Mercenary Spyware Jonny Evans / Computerworld : Apple doubles security bounty at Hexagon 2025 Zeljka Zorz / Help Net Security : Apple offers $2 million for zero-click exploit chains Sam Sabin / Axios : Apple offers hackers bug bounty of up to $2 million Michael Kan / PCMag : Find a Flaw, Earn Millions: Apple Gives Bug Bounty Payouts a Significant Boost William Gallagher / AppleInsider : Apple is about to give more generous payouts from its Bug Bounty Program Chance Miller / 9to5Mac : Apple announces ‘major evolution’ of its Security Bounty program: $2 million top award, more Amar Ćemanović / CyberInsider : Apple Offers $2 Million Bounty for Remote Zero-Click Exploits MacDailyNews : Apple will pay up to $2 million bug bounty reward Eduard Kovacs / SecurityWeek : Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid To Date Dennis Sellers / MacTech.com : Apple has announced a “major evolution” of its Security Bounty program, which will go into effect next month. … X: John Scott-Railton / @jsrailton : WOW: @Apple donating a thousand new #iPhone17 s to civil society at-risk from mercenary spyware. Good. This will help get Apple's most secure devices to where they need to be.. Truth is: those at the greatest risk from spyware are often least able to afford more secure phones [image] John Scott-Railton / @jsrailton : NEW: fresh trouble for mercenary spyware companies like NSO Group. @Apple launching substantial bounties on the zero-click exploits that feed the supply chain behind products like Pegasus & Paragon's Graphite. With bonuses, exploit developers can hit $5 million payouts. 1/ [image] John Scott-Railton / @jsrailton : @Apple 4/ It's also a clear signal that Apple announced this at @hexacon_fr, a major offensive security conference. https://x.com/... John Scott-Railton / @jsrailton : 3/ If I contemplating investing in spyware companies I'd want to carefully evaluate whether their exploit pipeline can match what @apple just threw down. https://security.apple.com/... @hexacon_fr : We're very honored to have Ivan Krstić (@radian) for our opening keynote. Don't miss that! [image] John Scott-Railton / @jsrailton : 2/ Apple is introducing Target Flags which speeds the process of getting exploits found & submitters rewarded. This faster tempo is also a strike against the mercenary spyware ecosystem. And the expanded categories also hit more widely against commercial surveillance vendors. [image] Arin Waichulis / @arinwaichulis : 🚨 Apple's Bounty Program just got a massive upgrade: top awards increasing BIGLY (now up to $2M for zero-click exploits), new “Target Flags” system pays researchers immediately upon verification, and now pays out $1K for low-impact finds Coming November https://9to5mac.com/... Bluesky: Catalin Cimpanu / @campuscodi.risky.biz : Watch out everyone... we're doubling the rewards we almost never pay [embedded post] Kim Zetter / @kimzetter : Apple announces new payouts for certain types of bugs - company will pay up to $2 million for anyone disclosing a chain of bugs that could be abused for spyware like Pegasus, as well as bonus awards for exploits that can bypass Lockdown Mode or are found while Apple software is still in beta testing Lily Hay Newman / @lhn : As Apple expands its bug bounty, I spoke with VP Ivan Krstić about the significance + recent big swings like Memory Integrity Enforcement.  These steps protect all users, but particularly those targeted by spyware: “We feel a great moral obligation to defend those users” www.wired.com/story/apple-... Andrew Couts / @couts : NEW: Apple is offering up to $2 million for exploits that can be used to infect iPhones with spyware, and bonuses for exploits used to bypass Lockdown Mode that bring total possible awards for a bug bounty to $5 million. @lhn.bsky.social reports: www.wired.com/story/apple-... Mastodon: Jeff Johnson / @lapcatsoftware@mastodon.social : RE: https://mastodon.online/...  A major evolution would be if Apple actually paid people who submitted bugs instead of arbitrarily deciding “nope” Dan Underwood / @danunderwood@mastodon.social : We're updating our bounty program with the top award now set at $2 million for zero-click remote exploit chains.  In addition - there are increased awards for proximate wireless attacks, WebKit, and Gatekeeper  —  https://security.apple.com/... Kim Zetter / @kimzetter@infosec.exchange : Apple has super-sized its bug-bounty program.  It will now pay up to $2 million to anyone disclosing a chain of bugs that can be used to install spyware like Pegsus and is also offering bonus awards for bugs that can be used to bypass Lockdown Mode https://security.apple.com/... Miguel de Icaza / @Migueldeicaza@mastodon.social : When you are an Apple security researcher, Christmas comes early on November 2025:  —  https://security.apple.com/... Thomas Bosboom / @thomasbosboom@infosec.exchange : A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research https://security.apple.com/... Forums: r/cybersecurity : Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits r/apple : A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research r/technews : Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits Lobsters : A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research Msmash / Slashdot : Apple Doubles Its Biggest Bug Bounty Reward To $2 Million Ars OpenForum : Apple ups the reward for finding major exploits to $2 million

Wired Lily Hay Newman

Context & Ripple Effects

Apple’s bounty has steadily broadened from a program centered on a few iOS and iCloud exploit areas to a 2019 expansion across Apple’s major operating systems, with the program opened to more researchers and its maximum award lifted to $1 million.

By 2022, Apple said the program had paid roughly $20 million, including multiple six-figure awards for high-impact findings. The new ceiling and faster-verification tools extend that established effort toward the most severe spyware-capable chains.

First-order effects

  • Researchers who can document qualifying zero-click remote-code-execution chains now have a substantially larger disclosed-reward path, with specified bonuses potentially raising a single finding’s payout to $5 million.
  • Apple adds Target Flags and expands bounty categories, aiming to shorten the path from a researcher’s report to verification and payment while prioritizing protections such as Lockdown Mode.

Second-order effects

  • A higher, clearer payout for the most valuable chains raises the economic appeal of reporting them to Apple rather than pursuing other buyers, though the program’s effectiveness will depend on speed and consistency of triage.
  • Other platform security teams may face pressure to reassess rewards and reporting workflows for comparable high-impact findings, particularly as Apple’s program moves beyond the earlier record of high-impact six-figure awards.

Third-order effects

  • If major vendors pair larger rewards with faster validation, bug bounties could become a more central channel for redirecting dual-use exploit research into coordinated remediation rather than private circulation.
  • The durable competition will shift from headline payout size alone to operational credibility: whether vendors can rapidly reproduce, patch, and fairly compensate for complex exploit chains.

The trend: Platform vendors are treating high-end vulnerability disclosure as ecosystem defense, competing on both payouts and the speed of turning researcher intelligence into fixes.

Discussion

  • @jsrailton John Scott-Railton on x
    WOW: @Apple donating a thousand new #iPhone17 s to civil society at-risk from mercenary spyware. Good. This will help get Apple's most secure devices to where they need to be.. Truth is: those at the greatest risk from spyware are often least able to afford more secure phones [im…
  • @jsrailton John Scott-Railton on x
    NEW: fresh trouble for mercenary spyware companies like NSO Group. @Apple launching substantial bounties on the zero-click exploits that feed the supply chain behind products like Pegasus & Paragon's Graphite. With bonuses, exploit developers can hit $5 million payouts. 1/ [image…
  • @jsrailton John Scott-Railton on x
    @Apple 4/ It's also a clear signal that Apple announced this at @hexacon_fr, a major offensive security conference. https://x.com/...
  • @jsrailton John Scott-Railton on x
    3/ If I contemplating investing in spyware companies I'd want to carefully evaluate whether their exploit pipeline can match what @apple just threw down. https://security.apple.com/...
  • @hexacon_fr @hexacon_fr on x
    We're very honored to have Ivan Krstić (@radian) for our opening keynote. Don't miss that! [image]
  • @jsrailton John Scott-Railton on x
    2/ Apple is introducing Target Flags which speeds the process of getting exploits found & submitters rewarded. This faster tempo is also a strike against the mercenary spyware ecosystem. And the expanded categories also hit more widely against commercial surveillance vendors. [im…
  • @arinwaichulis Arin Waichulis on x
    🚨 Apple's Bounty Program just got a massive upgrade: top awards increasing BIGLY (now up to $2M for zero-click exploits), new “Target Flags” system pays researchers immediately upon verification, and now pays out $1K for low-impact finds Coming November https://9to5mac.com/...
  • @campuscodi.risky.biz Catalin Cimpanu on bluesky
    Watch out everyone... we're doubling the rewards we almost never pay [embedded post]
  • @kimzetter Kim Zetter on bluesky
    Apple announces new payouts for certain types of bugs - company will pay up to $2 million for anyone disclosing a chain of bugs that could be abused for spyware like Pegasus, as well as bonus awards for exploits that can bypass Lockdown Mode or are found while Apple software is s…
  • @lhn Lily Hay Newman on bluesky
    As Apple expands its bug bounty, I spoke with VP Ivan Krstić about the significance + recent big swings like Memory Integrity Enforcement.  These steps protect all users, but particularly those targeted by spyware: “We feel a great moral obligation to defend those users” www.wire…
  • @couts Andrew Couts on bluesky
    NEW: Apple is offering up to $2 million for exploits that can be used to infect iPhones with spyware, and bonuses for exploits used to bypass Lockdown Mode that bring total possible awards for a bug bounty to $5 million. @lhn.bsky.social reports: www.wired.com/story/apple-...
  • @lapcatsoftware@mastodon.social Jeff Johnson on mastodon
    RE: https://mastodon.online/...  A major evolution would be if Apple actually paid people who submitted bugs instead of arbitrarily deciding “nope”
  • @danunderwood@mastodon.social Dan Underwood on mastodon
    We're updating our bounty program with the top award now set at $2 million for zero-click remote exploit chains.  In addition - there are increased awards for proximate wireless attacks, WebKit, and Gatekeeper  —  https://security.apple.com/...
  • @Migueldeicaza@mastodon.social Miguel de Icaza on mastodon
    When you are an Apple security researcher, Christmas comes early on November 2025:  —  https://security.apple.com/...
  • r/cybersecurity r on reddit
    Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits
  • r/apple r on reddit
    A major evolution of Apple Security Bounty, with the industry's top awards for the most advanced research - Apple Security Research
  • r/technews r on reddit
    Apple Announces $2 Million Bug Bounty Reward for the Most Dangerous Exploits