Apple expands bug bounty to macOS, watchOS, and Apple TV, increases maximum payout to $1M, and will open the program to all researchers this fall
And a Bigger Bug Bounty The Hacker News : Apple will now pay hackers up to $1 million for reporting vulnerabilities Charlotte Henry / The Mac Observer : Apple Offers New Bug Bounty of up to $1.5 Million Juli Clover / MacRumors : Apple Ups Bug Bounty Payouts, Expands Access to All Researchers and Launches macOS Program Zack Whittaker / TechCrunch : Apple expands its bug bounty, increases maximum payout to $1M Firstpost Tech : Apple bug bounty program offers up to $1 mn to hackers who find flaws in iPhones and Macs Tom Warren / The Verge : Apple reveals special new iPhones for security researchers Gary Ng / iPhone in Canada Blog : Apple to Pay Up to $1M for Researchers to Find iPhone and Now Mac Security Flaws Joseph Menn / Reuters : Apple offers record ‘bounty’ to researchers who find iPhone security flaws Shaun Nichols / The Register : Pwn an iPhone to bank $1m and Check Point gripes about WhatsApp privacy again Tweets: Tom Warren / @tomwarren : Apple is launching special new iPhones for security researchers in 2020. These handsets will include ssh, root shell, and advanced debug capabilities. Details here: https://www.theverge.com/... https://twitter.com/... Thomas Brewster / @iblametom : Well, what did I tell you? Apple confirms $1m bug bounty reward - requires owning the iPhone kernel with zero clicks. https://www.forbes.com/... https://twitter.com/...
Context & Ripple Effects
Apple's bounty program began as a gatekept experiment: an invite-only program with a few dozen researchers and a $200K ceiling. Three years on, the company is tripling that ceiling to $1M, extending coverage beyond iOS to macOS, watchOS, and Apple TV, and promising open enrollment to all researchers this fall.
The move pairs money with access — Apple is also handing researchers special iPhones with debug capabilities, acknowledging that locked-down consumer hardware limits legitimate exploitation work. The December eligibility-and-payout guidelines published alongside the opening (published criteria and categories) show Apple building the program into standing infrastructure rather than a PR gesture.
First-order effects
- Security researchers who previously had no path into Apple's program can now submit macOS, watchOS, and Apple TV findings for payment, with high-severity chains worth up to $1M instead of $200K.
Second-order effects
- A $1M published ceiling gives independent researchers a benchmark against gray-market exploit buyers, raising the opportunity cost of selling Apple flaws privately and pressuring other platform vendors' bounty maximums.
Third-order effects
- If the pattern holds — Apple later reported ~$20M in cumulative awards including twenty $100K+ payouts, then doubled the top award again to $2M for spyware-capable chains in its 2025 'major evolution' — vendor bounties become a durable pricing floor for zero-day research, shifting exploit economics from brokers toward corporate programs.
The trend: Platform vendors are converting ad-hoc bug bounties into institutionalized vulnerability markets whose escalating top prizes increasingly compete with gray-market exploit prices.